Bug 2416818 (CVE-2025-13466)

Summary: CVE-2025-13466 body-parser: body-parser denial of service
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, abarbaro, abrianik, abuckta, alcohan, alizardo, amctagga, anjoseph, anpicker, anthomas, aoconnor, aprice, asoldano, ataylor, bbaranow, bbrownin, bdettelb, bmaxwell, bniver, brasmith, brian.stansberry, carogers, caswilli, cmah, cochase, darran.lofthouse, dbosanac, dbruscin, dhanak, dkuc, doconnor, dosoudil, dranck, drosa, dsimansk, dymurray, eaguilar, ebaron, ehelms, erezende, eric.wittmann, flucifre, ggainey, ggrzybek, gmalinko, gmeno, gparvin, groman, haoli, hasun, hkataria, ibek, ibolton, istudens, ivassile, iweiss, jajackso, janstey, jbalunas, jcammara, jcantril, jchui, jfula, jhe, jkoehler, jmatthew, jmitchel, jmontleo, jneedle, jolong, jowilson, jprabhak, jreimann, jrokos, juwatts, jwong, kaycoth, kegrant, kingland, koliveir, kshier, ktsao, kvanderr, kverlaen, lball, lphiri, mabashia, manissin, matzew, mbenjamin, mdessi, mhackett, mhulan, mnovotny, mosmerov, mpierce, mrizzi, msvehla, mwringe, nboldt, ngough, nipatil, nmoumoul, nwallace, nyancey, omaciel, ometelka, orabin, osousa, owatkins, pahickey, pantinor, parichar, pbizzarr, pbraun, pcattana, pcreech, pdelbell, pesilva, pgaikwad, pjindal, pmackay, psrna, ptisnovs, rchan, rhaigner, rjohnson, rkubis, rojacob, rstancel, rstepani, sausingh, sdawley, shvarugh, simaishi, slucidi, smaestri, smallamp, smcdonal, sostapov, sseago, stcannon, syedriko, tasato, teagle, tfister, thavo, tmalecek, tom.jenkinson, ttakamiy, vereddy, veshanka, wtam, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
body-parser is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large numbers of parameters. An attacker can send payloads containing thousands of parameters within the default 100KB request size limit, causing elevated CPU and memory usage. This can lead to service slowdown or partial outages under sustained malicious traffic.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2418498, 2418501, 2418503, 2418512, 2418514, 2418493, 2418494, 2418495, 2418496, 2418497, 2418499, 2418500, 2418502, 2418504, 2418505, 2418506, 2418507, 2418508, 2418509, 2418510, 2418511, 2418513, 2418515, 2418516    
Bug Blocks:    

Description OSIDB Bzimport 2025-11-24 19:01:13 UTC
body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large numbers of parameters. An attacker can send payloads containing thousands of parameters within the default 100KB request size limit, causing elevated CPU and memory usage. This can lead to service slowdown or partial outages under sustained malicious traffic.
This issue is addressed in version 2.2.1.