[GHSA-wqch-xfxh-vrr4] body-parser is vulnerable to denial of service when url encoding is used#6469
Conversation
|
Hi there @UlisesGascon! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
There was a problem hiding this comment.
Pull request overview
This PR corrects a security advisory for body-parser to accurately specify that only version 2.2.0 is affected by CVE-2025-13466 (a denial of service vulnerability), preventing false positive alerts for users running unaffected versions. The previous advisory incorrectly indicated all versions prior to 2.2.1 were vulnerable.
- Updated the
introducedversion in the affected range from"0"to"2.2.0" - Added explicit
versionsarray to clearly identify 2.2.0 as the only affected version - Removed the CVSS v4 scoring section (CVSS v3 remains)
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
This PR was replaced by #6470 |
Updates
Comments
the current range < 2.2.1 is incorrect and causing false alerts for unaffected users. Only 2.2.0 is affected see