Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Update dependency body-parser to v1.20.3 [SECURITY]#100

Open
ot-renovate[bot] wants to merge 1 commit into
main from
renovate/npm-body-parser-vulnerability
Open

Update dependency body-parser to v1.20.3 [SECURITY] #100
ot-renovate[bot] wants to merge 1 commit into
main from
renovate/npm-body-parser-vulnerability

Conversation

@ot-renovate

@ot-renovate ot-renovate Bot commented Sep 21, 2024
edited
Loading

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
body-parser dependencies patch 1.20.21.20.3

body-parser vulnerable to denial of service when url encoding is enabled

CVE-2024-45590 / GHSA-qwcr-r2fm-qrc7

More information

Details

Impact

body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service.

Patches

this issue is patched in 1.20.3

References

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

expressjs/body-parser (body-parser)

v1.20.3

Compare Source

===================

  • deps: qs@​6.13.0
  • add depth option to customize the depth level in the parser
  • IMPORTANT: The default depth level for parsing URL-encoded data is now 32 (previously was Infinity)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by OT Renovate Bot.

@ot-renovate ot-renovate Bot force-pushed the renovate/npm-body-parser-vulnerability branch from 88611e9 to 8ee5fb3 Compare November 25, 2025 16:10
@ot-renovate ot-renovate Bot changed the title (削除) chore(deps): update dependency body-parser to v1.20.3 [security] (削除ここまで) (追記) chore(deps): update dependency body-parser to v2 [security] (追記ここまで) Nov 25, 2025
@ot-renovate ot-renovate Bot force-pushed the renovate/npm-body-parser-vulnerability branch from 8ee5fb3 to 2e1b4ac Compare November 25, 2025 19:04
@ot-renovate ot-renovate Bot changed the title (削除) chore(deps): update dependency body-parser to v2 [security] (削除ここまで) (追記) chore(deps): update dependency body-parser to v1.20.3 [security] (追記ここまで) Nov 25, 2025
@ot-renovate ot-renovate Bot changed the title (削除) chore(deps): update dependency body-parser to v1.20.3 [security] (削除ここまで) (追記) chore(deps): update dependency body-parser to v1.20.3 [security] - autoclosed (追記ここまで) Mar 2, 2026
@ot-renovate ot-renovate Bot deleted the renovate/npm-body-parser-vulnerability branch March 2, 2026 03:35
@ot-renovate ot-renovate Bot changed the title (削除) chore(deps): update dependency body-parser to v1.20.3 [security] - autoclosed (削除ここまで) (追記) chore(deps): update dependency body-parser to v1.20.3 [security] (追記ここまで) Mar 2, 2026
@ot-renovate ot-renovate Bot force-pushed the renovate/npm-body-parser-vulnerability branch 2 times, most recently from 2e1b4ac to f86b4e1 Compare March 2, 2026 06:36
@ot-renovate ot-renovate Bot changed the title (削除) chore(deps): update dependency body-parser to v1.20.3 [security] (削除ここまで) (追記) chore(deps): update dependency body-parser to v1.20.3 [security] - autoclosed (追記ここまで) Mar 27, 2026
@ot-renovate ot-renovate Bot changed the title (削除) chore(deps): update dependency body-parser to v1.20.3 [security] - autoclosed (削除ここまで) (追記) chore(deps): update dependency body-parser to v1.20.3 [security] (追記ここまで) Mar 30, 2026
@ot-renovate ot-renovate Bot force-pushed the renovate/npm-body-parser-vulnerability branch 2 times, most recently from f86b4e1 to 3f40826 Compare March 30, 2026 18:35
@ot-renovate ot-renovate Bot changed the title (削除) chore(deps): update dependency body-parser to v1.20.3 [security] (削除ここまで) (追記) chore(deps): update dependency body-parser to v1.20.3 [security] - autoclosed (追記ここまで) Apr 27, 2026
@ot-renovate ot-renovate Bot changed the title (削除) chore(deps): update dependency body-parser to v1.20.3 [security] - autoclosed (削除ここまで) (追記) chore(deps): update dependency body-parser to v1.20.3 [security] (追記ここまで) Apr 27, 2026
@ot-renovate ot-renovate Bot force-pushed the renovate/npm-body-parser-vulnerability branch 2 times, most recently from 3f40826 to 58bf528 Compare April 27, 2026 18:31
@ot-renovate ot-renovate Bot changed the title (削除) chore(deps): update dependency body-parser to v1.20.3 [security] (削除ここまで) (追記) Update dependency body-parser to v1.20.3 [SECURITY] (追記ここまで) May 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

0 participants

AltStyle によって変換されたページ (->オリジナル) /