Resource exhaustion in body-parser - CVE-2025-13466

 

Resource exhaustion in body-parser - CVE-2025-13466

Published: November 25, 2025


Vulnerability identifier: #VU118753
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-13466
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when handling URL-encoded bodies with very large numbers of parameters. A remote attacker can trigger high CPU and memory usage and perform a denial of service (DoS) attack.


Affected software

body-parser
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM DataPower Gateway
IBM App Connect Enterprise
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
MongoDB Enterprise Advanced with IBM

How to mitigate CVE-2025-13466

Install updates from vendor's website.

body-parser - update to 2.2.1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.17-sc2, 4.3.1
IBM DataPower Gateway - addressed in versions 10.6.0.9, 11.0.0.0
IBM App Connect Enterprise - addressed in versions 12.0.12.21, 13.0.6.0
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.20, 16.1.3.1
MongoDB Enterprise Advanced with IBM - update to 1.48.3

External References

Related Security Bulletins