VDB
Sign up
HIGH7.5

GHSA-qwcr-r2fm-qrc7

body-parser vulnerable to denial of service when url encoding is enabled

Quick fix

GHSA-qwcr-r2fm-qrc7 — body-parser: upgrade to the fixed version with the command below.

npm install body-parser@1.20.3

Details

### Impact

body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service.

### Patches

this issue is patched in 1.20.3

### References

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/body-parser
Introduced in: 0Fixed in: 1.20.3
Fixnpm install body-parser@1.20.3

References