-
Notifications
You must be signed in to change notification settings - Fork 61
chore(deps): update dependency body-parser to >=1.20.4 [security] #3510
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
main
Choose a base branch
from
renovate/npm-body-parser-vulnerability
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+2
−2
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
882747b to
c86dc68
Compare
c86dc68 to
7e6ce28
Compare
4ed5552 to
9c49b6d
Compare
be535dc to
78ac0df
Compare
78ac0df to
02ff747
Compare
02ff747 to
72ecc49
Compare
72ecc49 to
af78422
Compare
af78422 to
b1a9273
Compare
b1a9273 to
64ce734
Compare
64ce734 to
73dc27b
Compare
1f6b72e to
675bcdd
Compare
675bcdd to
5136c97
Compare
5136c97 to
7e399bc
Compare
4c4fbd5 to
752ad5f
Compare
03b5d39 to
6b0a064
Compare
54c60c1 to
c4e5983
Compare
61dd503 to
8c61945
Compare
77dae58 to
81b2db1
Compare
81b2db1 to
34f420e
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
>=1.20.3→>=1.20.4GitHub Vulnerability Alerts
CVE-2025-13466
Impact
body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large numbers of parameters. An attacker can send payloads containing thousands of parameters within the default 100KB request size limit, causing elevated CPU and memory usage. This can lead to service slowdown or partial outages under sustained malicious traffic.
Patches
This issue is addressed in version 2.2.1.
Release Notes
expressjs/body-parser (body-parser)
v1.20.4Compare Source
===================
Configuration
📅 Schedule: Branch creation - "" in timezone Asia/Tokyo, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.