CVE-2025-13466

MEDIUM

body-parser 2.2.0 - Denial of Service via URL-Encoded Parameter Flood

Title source: llm
STIX 2.1

Description

body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large numbers of parameters. An attacker can send payloads containing thousands of parameters within the default 100KB request size limit, causing elevated CPU and memory usage. This can lead to service slowdown or partial outages under sustained malicious traffic. This issue is addressed in version 2.2.1.

References (1)

Core 1

Scores

CVSS v4 5.5
EPSS 0.0003
EPSS Percentile 10.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:P/AU:Y

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (2)
body-parser/body-parser 2.2.0
npm/body-parser 2.2.0 - 2.2.1npm
Published Nov 24, 2025
Tracked Since Feb 18, 2026