Known vulnerabilities in body-parser
Vendor:
Express.js
Software:
body-parser
Software CPE:
cpe:2.3:a:expressjs:body-parser:*:*:*:*:*:*:*:*
Website:
https://expressjs.com/
Total vulnerabilities:
3
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
1.20.6
2.3.0
1.20.5
2.2.2
1.20.4
2.2.1
2.2.0
2.1.0
2.0.2
2.0.1
2.0.0
1.20.3
1.20.2
1.20.1
1.20.0
1.19.2
1.19.1
1.19.0
1.18.3
1.18.2
1.18.1
1.18.0
1.17.2
1.17.1
1.17.0
1.16.1
1.16.0
1.15.2
1.15.1
1.15.0
1.14.2
1.14.1
1.14.0
1.13.3
1.13.2
1.13.1
1.13.0
1.12.4
1.12.3
1.12.2
1.12.1
1.12.0
1.11.0
1.10.2
1.10.1
1.10.0
1.9.3
1.9.2
1.9.1
1.9.0
1.8.4
1.8.3
1.8.2
1.8.1
1.8.0
1.7.0
1.6.7
1.6.6
1.6.5
1.6.4
1.6.3
1.6.2
1.6.1
1.6.0
1.5.2
1.5.1
1.5.0
1.4.3
1.4.2
1.4.1
1.4.0
1.3.1
1.3.0
1.2.2
1.2.1
1.2.0
1.1.2
1.1.1
1.1.0
1.0.2
1.0.1
1.0.0
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU137284 - Allocation of Resources Without Limits or Throttling CVE-2026-12590 |
CWE-770 | Low | 1.20.6, 2.3.0 | 09.07.2026 |
SB2026070953 |
||
| #VU118753 - Resource exhaustion CVE-2025-13466 |
CWE-400 | Medium | 2.2.1 | 25.11.2025 |
SB2025112551 SB2026012034 SB2026022521 and 2 more |
||
| #VU97208 - Asymmetric Resource Consumption (Amplification) CVE-2024-45590 |
CWE-405 | Medium | 1.20.3 | 12.09.2024 |
SB2024091249 SB2024091251 SB2024091252 and 59 more |