CVE-2025-13466 - CVE House
Back to Database
Status published Medium CVE-2025-13466

body-parser vulnerable to denial of service when url encoding is used

Vulnerability Description

body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large numbers of parameters. An attacker can send payloads containing thousands of parameters within the default 100KB request size limit, causing elevated CPU and memory usage. This can lead to service slowdown or partial outages under sustained malicious traffic. This issue is addressed in version 2.2.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13466

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Phillip Barta
  • Sebastian Beltran
  • Ulises Gascón
  • Chris de Almeida
  • Jean Burellier

Affected Vendor

body-parser

View all reports →

Affected Software

body-parser
Vulnerable Versions:
2.2.0

Timeline

Official Publish: November 24th, 2025
Last Modified: November 24th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)