HIGH🇬🇧 English

CVE-2024-45590

CVSS 7.5v3.1pub. 2024-09-10upd. 2024-09-20

body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Openjsf Body Parser

    APP
    Openjsf
    < 1.20.3
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
DoS
CWE
Referencje

Powiązane podatności

CVE-2026-12590LOW3.7ten sam produkt

W wersjach body-parser wcześniejszych niż 1.20.6 (linia 1.x) i 2.3.0 (linia 2.x), gdy parser jest skonfigurowa...

CVE-2026-25244CRITICAL9.8PL ✓ten sam vendor

WebdriverIO: command injection w orkiestracji testów prowadzący do RCE

CVE-2026-84394HIGH7.5ten sam vendor

fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error....

CVE-2026-84292HIGH7.5ten sam vendor

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the use...

CVE-2026-75899HIGH7.5ten sam vendor

fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes...