#VU118753 Resource exhaustion in body-parser - CVE-2025-13466
Published: November 25, 2025
body-parser
Express.js
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling URL-encoded bodies with very large numbers of parameters. A remote attacker can trigger high CPU and memory usage and perform a denial of service (DoS) attack.