Denial of Service Vulnerability in body-parser by Express.js
CVE-2025-13466

5.5MEDIUM

Key Information:

Vendor
CVE Published:
24 November 2025

What is CVE-2025-13466?

The body-parser module version 2.2.0 is susceptible to a denial of service vulnerability due to its inefficient processing of URL-encoded bodies containing an excessive number of parameters. Attackers can leverage this weakness by transmitting payloads with thousands of parameters, which can exceed the standard 100KB request size limit. This behavior can lead to increased CPU and memory consumption, potentially causing significant service slowdowns or partial outages under continual malicious requests. Users are encouraged to upgrade to version 2.2.1 to mitigate this issue.

Affected Version(s)

body-parser 2.2.0

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phillip Barta
Sebastian Beltran
Ulises GascĂłn
Chris de Almeida
Jean Burellier
.
CVE-2025-13466 : Denial of Service Vulnerability in body-parser by Express.js