CVE-2026-12590Patch(openjsf / body-parser)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openjsf body-parser systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-parser 1.20.6 and 2.3.0. After the fix, invalid limit values throw a clear error at parser construction time instead of silently disabling enforcement, while null and undefined continue to fall back to the default limit of 100kb. Workarounds: Validate the limit value before passing it to body-parser. For example, parse the value at startup and reject any configuration where the result is null or a non-finite number.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • body-parser

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
body-parser

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-09: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-09: 107-09
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Ulises Gascón@kom_256
    Patch

    🚨 Low-severity security fix in body-parser 1.20.6 & 2.3.0 released. Patches CVE-2026-12590: denial of service when invalid limit value silently disables size enforcement. https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6

    Post summary

    The advisory announces that low‑severity CVE‑2026‑12590, a DoS flaw triggered by an invalid limit value in body‑parser, is patched in versions 1.20.6 and 2.3.0.

    00000173
    5.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenjsfbody-parser-node.js-

Explore more