Denial of Service Vulnerability in body-parser by Express.js
CVE-2025-13466
What is CVE-2025-13466?
The body-parser module version 2.2.0 is susceptible to a denial of service vulnerability due to its inefficient processing of URL-encoded bodies containing an excessive number of parameters. Attackers can leverage this weakness by transmitting payloads with thousands of parameters, which can exceed the standard 100KB request size limit. This behavior can lead to increased CPU and memory consumption, potentially causing significant service slowdowns or partial outages under continual malicious requests. Users are encouraged to upgrade to version 2.2.1 to mitigate this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
body-parser 2.2.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
