body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service.
this issue is patched in 1.20.3
{
"nvd_published_at": "2024-09-10T16:15:21Z",
"severity": "HIGH",
"github_reviewed_at": "2024-09-10T15:52:39Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-405"
]
}