-
-
Notifications
You must be signed in to change notification settings - Fork 1.8k
chore(deps): update dependency body-parser to v2.2.1 [security] #5776
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: next
Are you sure you want to change the base?
Conversation
Deploying egg-v3 with
|
| Latest commit: |
9da47d8
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://56474a05.egg-v3.pages.dev |
| Branch Preview URL: | https://renovate-npm-body-parser-vul.egg-v3.pages.dev |
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Comment |
Deploying egg with
|
| Latest commit: |
9da47d8
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://781434f3.egg-cci.pages.dev |
| Branch Preview URL: | https://renovate-npm-body-parser-vul.egg-cci.pages.dev |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## next #5776 +/- ##
=======================================
Coverage 87.57% 87.57%
=======================================
Files 563 563
Lines 10940 10940
Branches 1242 1242
=======================================
Hits 9581 9581
Misses 1275 1275
Partials 84 84 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
This PR contains the following updates:
2.2.0→2.2.1GitHub Vulnerability Alerts
CVE-2025-13466
Impact
body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large numbers of parameters. An attacker can send payloads containing thousands of parameters within the default 100KB request size limit, causing elevated CPU and memory usage. This can lead to service slowdown or partial outages under sustained malicious traffic.
Patches
This issue is addressed in version 2.2.1.
Release Notes
expressjs/body-parser (body-parser)
v2.2.1Compare Source
=========================
encodingExistsby using prototype-less objectsConfiguration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.