CVE-2025-13466
Last modified
CVE-2025-13466 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large numbers of parameters. An attacker can send payloads containing thousands of parameters within the default 100KB request size limit, causing elevated CPU and memory usage. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large numbers of parameters. An attacker can send payloads containing thousands of parameters within the default 100KB request size limit, causing elevated CPU and memory usage. This can lead to service slowdown or partial outages under sustained malicious traffic. This issue is addressed in version 2.2.1.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-13466?
How severe is CVE-2025-13466?
How do I fix CVE-2025-13466?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-13457The WooCommerce Square plugin for WordPress is vulnerable to…7.5
- CVE-2025-13459IBM Aspera Console 3.3.0 through 3.4.8 could allow a privile…4.9
- CVE-2025-13460IBM Aspera Console 3.3.0 through 3.4.8 could allow an attack…5.3
- CVE-2025-13462The "tarfile" module would still apply normalization of AREG…3.3
- CVE-2025-13463The Bold Page Builder plugin for WordPress is vulnerable to …6.4
- CVE-2025-13465Lodash versions 4.0.0 through 4.17.22 are vulnerable to prot…5.3
- CVE-2025-13467A flaw was found in the Keycloak LDAP User Federation provid…5.5
- CVE-2025-13468A weakness has been identified in SourceCodester Alumni Mana…8.1
- CVE-2025-13469A security vulnerability has been detected in Public Knowled…4.8
- CVE-2025-13470In RNP version 0.18.0 a refactoring regression causes the sy…7.7
- CVE-2025-13471The User Activity Log WordPress plugin through 2.2 does not …5.3
- CVE-2025-13472A fix was made in BlazeMeter Jenkins Plugin version 4.27 to …5.3
Are you affected by CVE-2025-13466?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
