Denial of Service Vulnerability in Servify Express Node.js Package
CVE-2025-67731
What is CVE-2025-67731?
The Servify Express package for Node.js, prior to version 1.2, contains a vulnerability that allows untrusted clients to send excessively large JSON request bodies. This may lead to overwhelming memory usage, reduced performance, or even process crashes, causing a Denial of Service (DoS). The vulnerability arises from a lack of request size limits in the express.json() parser. It is crucial for developers using this package to upgrade to version 1.2 and implement size limits on the JSON parser or utilize reverse proxies to manage request sizes effectively.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
servify-express < 1.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
