GHSA-v422-hmwv-36x6

    Dashboard / Vulnerabilities / GHSA-v422-hmwv-36x6

    GHSA-v422-hmwv-36x6

    Published: 20 Jul 2026Last Modified: 10 Sept 2026

    Summary: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement

    Details: ### Impact When body-parser is configured with an invalid `limit` option value, such as an unparseable string or `NaN`, `bytes.parse()` returns `null` and the request body size check is silently skipped. Applications that rely on `limit` as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. This issue affects applications that pass a programmatically computed or user-configurable value to the `limit` option without validating it first. ### Patches This issue is fixed in [[email protected]](https://github.com/expressjs/body-parser/releases/tag/v2.3.0) and [[email protected]](https://github.com/expressjs/body-parser/releases/tag/v1.20.6) via [#698](https://github.com/expressjs/body-parser/pull/698). After the fix, invalid `limit` values throw a clear error at parser construction time instead of silently disabling enforcement. `null` and `undefined` continue to fall back to the default limit (`100kb`). ### Workarounds Validate `limit` before passing it to body-parser. For example, parse the value with [`bytes.parse()`](https://github.com/visionmedia/bytes.js) at startup and reject any configuration where it returns `null` or a non-finite number. ### References - [#698](https://github.com/expressjs/body-parser/pull/698): fix PR - [bytes.js](https://github.com/visionmedia/bytes.js): limit parser

    Affected packages

    Package

    Name: body-parser

    Purl: pkg:npm/body-parser

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.20.6

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High