CVE-2024-45590
body-parser vulnerable to denial of service when url encoding is enabled
- Published
- Sep 10, 2024
- Updated
- Sep 10, 2024
- Assigning CNA
- GitHub_M
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HLow · next 30 days
- Percentile
- 55.4%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.
Sources
2Proof-of-concept exploit for CVE-2024-45590, demonstrating unauthenticated remote code execution in a WordPress plugin via arbitrary file upload. Includes Docker-based vulnerable environment and automated scanner.
Exploit for CVE-2024-45590 vulnerability, providing proof-of-concept code for security testing and vulnerability verification.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.