Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Nov 25, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
body-parser >=1.20.3>=1.20.4 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2025-13466

Impact

body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large numbers of parameters. An attacker can send payloads containing thousands of parameters within the default 100KB request size limit, causing elevated CPU and memory usage. This can lead to service slowdown or partial outages under sustained malicious traffic.

Patches

This issue is addressed in version 2.2.1.


Release Notes

expressjs/body-parser (body-parser)

v1.20.4

Compare Source

===================

  • deps: qs@~6.14.0
  • deps: use tilde notation for dependencies
  • deps: http-errors@~2.0.1
  • deps: raw-body@~2.5.3

Configuration

📅 Schedule: Branch creation - "" in timezone Asia/Tokyo, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from a team as a code owner November 25, 2025 18:31
@renovate renovate bot added the renovate label Nov 25, 2025
@renovate renovate bot requested review from chihiro-adachi and shabaraba and removed request for a team November 25, 2025 18:31
@renovate renovate bot added the renovate label Nov 25, 2025
@renovate renovate bot changed the title chore(deps): update dependency body-parser to v2 [security] chore(deps): update dependency body-parser to >=1.20.4 [security] Dec 1, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch from 882747b to c86dc68 Compare December 1, 2025 19:16
@renovate renovate bot changed the title chore(deps): update dependency body-parser to >=1.20.4 [security] chore(deps): update dependency body-parser to v2 [security] Dec 1, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch from c86dc68 to 7e6ce28 Compare December 1, 2025 21:00
@renovate renovate bot changed the title chore(deps): update dependency body-parser to v2 [security] chore(deps): update dependency body-parser to >=1.20.4 [security] Dec 1, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch 2 times, most recently from 4ed5552 to 9c49b6d Compare December 2, 2025 01:53
@renovate renovate bot changed the title chore(deps): update dependency body-parser to >=1.20.4 [security] chore(deps): update dependency body-parser to v2 [security] Dec 2, 2025
@renovate renovate bot changed the title chore(deps): update dependency body-parser to v2 [security] chore(deps): update dependency body-parser to >=1.20.4 [security] Dec 3, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch 2 times, most recently from be535dc to 78ac0df Compare December 3, 2025 18:26
@renovate renovate bot changed the title chore(deps): update dependency body-parser to >=1.20.4 [security] chore(deps): update dependency body-parser to v2 [security] Dec 3, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch from 78ac0df to 02ff747 Compare December 3, 2025 21:59
@renovate renovate bot changed the title chore(deps): update dependency body-parser to v2 [security] chore(deps): update dependency body-parser to >=1.20.4 [security] Dec 3, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch from 02ff747 to 72ecc49 Compare December 3, 2025 22:00
@renovate renovate bot changed the title chore(deps): update dependency body-parser to >=1.20.4 [security] chore(deps): update dependency body-parser to v2 [security] Dec 4, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch from 72ecc49 to af78422 Compare December 4, 2025 03:58
@renovate renovate bot changed the title chore(deps): update dependency body-parser to v2 [security] chore(deps): update dependency body-parser to >=1.20.4 [security] Dec 4, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch from af78422 to b1a9273 Compare December 4, 2025 14:07
@renovate renovate bot changed the title chore(deps): update dependency body-parser to >=1.20.4 [security] chore(deps): update dependency body-parser to v2 [security] Dec 4, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch from b1a9273 to 64ce734 Compare December 4, 2025 17:45
@renovate renovate bot changed the title chore(deps): update dependency body-parser to v2 [security] chore(deps): update dependency body-parser to >=1.20.4 [security] Dec 4, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch from 64ce734 to 73dc27b Compare December 4, 2025 17:46
@renovate renovate bot changed the title chore(deps): update dependency body-parser to >=1.20.4 [security] chore(deps): update dependency body-parser to v2 [security] Dec 4, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch 2 times, most recently from 1f6b72e to 675bcdd Compare December 17, 2025 22:11
@renovate renovate bot changed the title chore(deps): update dependency body-parser to >=1.20.4 [security] chore(deps): update dependency body-parser to v2 [security] Dec 17, 2025
@renovate renovate bot changed the title chore(deps): update dependency body-parser to v2 [security] chore(deps): update dependency body-parser to >=1.20.4 [security] Dec 18, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch from 675bcdd to 5136c97 Compare December 18, 2025 15:33
@renovate renovate bot changed the title chore(deps): update dependency body-parser to >=1.20.4 [security] chore(deps): update dependency body-parser to v2 [security] Dec 18, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch from 5136c97 to 7e399bc Compare December 18, 2025 17:29
@renovate renovate bot changed the title chore(deps): update dependency body-parser to v2 [security] chore(deps): update dependency body-parser to >=1.20.4 [security] Dec 18, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch 2 times, most recently from 4c4fbd5 to 752ad5f Compare December 18, 2025 22:10
@renovate renovate bot changed the title chore(deps): update dependency body-parser to >=1.20.4 [security] chore(deps): update dependency body-parser to v2 [security] Dec 18, 2025
@renovate renovate bot changed the title chore(deps): update dependency body-parser to v2 [security] chore(deps): update dependency body-parser to >=1.20.4 [security] Dec 19, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch 2 times, most recently from 03b5d39 to 6b0a064 Compare December 19, 2025 21:54
@renovate renovate bot changed the title chore(deps): update dependency body-parser to >=1.20.4 [security] chore(deps): update dependency body-parser to v2 [security] Dec 19, 2025
@renovate renovate bot changed the title chore(deps): update dependency body-parser to v2 [security] chore(deps): update dependency body-parser to >=1.20.4 [security] Dec 23, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch 2 times, most recently from 54c60c1 to c4e5983 Compare December 23, 2025 21:38
@renovate renovate bot changed the title chore(deps): update dependency body-parser to >=1.20.4 [security] chore(deps): update dependency body-parser to v2 [security] Dec 23, 2025
@renovate renovate bot changed the title chore(deps): update dependency body-parser to v2 [security] chore(deps): update dependency body-parser to >=1.20.4 [security] Dec 29, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch 2 times, most recently from 61dd503 to 8c61945 Compare December 29, 2025 21:54
@renovate renovate bot changed the title chore(deps): update dependency body-parser to >=1.20.4 [security] chore(deps): update dependency body-parser to v2 [security] Dec 29, 2025
@renovate renovate bot changed the title chore(deps): update dependency body-parser to v2 [security] chore(deps): update dependency body-parser to >=1.20.4 [security] Dec 31, 2025
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch 2 times, most recently from 77dae58 to 81b2db1 Compare December 31, 2025 21:32
@renovate renovate bot changed the title chore(deps): update dependency body-parser to >=1.20.4 [security] chore(deps): update dependency body-parser to v2 [security] Dec 31, 2025
@renovate renovate bot changed the title chore(deps): update dependency body-parser to v2 [security] chore(deps): update dependency body-parser to >=1.20.4 [security] Jan 2, 2026
@renovate renovate bot force-pushed the renovate/npm-body-parser-vulnerability branch from 81b2db1 to 34f420e Compare January 2, 2026 00:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant