CVE-2025-13466

body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large numbers of parameters. An attacker can send payloads containing thousands of parameters within the default 100KB request size limit, causing elevated CPU and memory usage. This can lead to service slowdown or partial outages under sustained malicious traffic. This issue is addressed in version 2.2.1.
CVSS

No CVSS.

Configurations

No configuration.

History

24 Nov 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-24 19:15

Updated : 2025-11-25 22:16


NVD link : CVE-2025-13466

Mitre link : CVE-2025-13466

CVE.ORG link : CVE-2025-13466


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption