CVE-2024-45590: Openjsf Body-Parser

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.

Affected products

  • Openjsf Body-Parser: before 1.20.3 (fixed in 1.20.3)

Published 2024-09-10. Last modified 2026-06-17.