CVE-2024-45590
body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.
- Affected products
- Bitbucket, Debian, Body-Parser
- Openjsf Body-parser
- < 1.20.3
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.8% (54th percentile)
- Weakness
- CWE-405
- NVD status
- Analyzed
- Published
- 2024-09-10
CVE-2024-45590 at NVD
1 known exploit for CVE-2024-45590
Proof-of-concept code and exploit modules indexed by Sploitus