CVE-2024-45590

body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.

  • Published Sep 10, 2024
  • CVSS 7.5 high
  • 0.8% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

In the news

CVE-2024-45590 at the National Vulnerability Database