CVE-2024-45590
📛 CVE Title
body-parser vulnerable to denial of service when url encoding is enabled
Description
body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- GitHub_M
- CVSS severity
- HIGH
- CVSS score
- 7.5 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Effective score
- 7.5 / 10 HIGH source: CNA overview
- MSRC score
- 7.5 / 10 HIGH
- CWE(s)
-
CWE-405 - Reserved
- 2024-09-02
- Published
- 2024-09-10 17:54 UTC
- Last updated
- 2024-09-10 20:47 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/45xxx/CVE-2024-45590.json
- Linked Threat
- CVE-2024-45590 — body-parser vulnerable to denial of service when url encoding is enabled
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2024-09-10 16:15:21 UTC
- NVD last modified
- 2026-06-17 07:54:31 UTC
- NVD CVSS v3.1
- 7.5 / 10 HIGH source: security-advisories@github.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 3.6 / 10
- EPSS score
- 0.0082 (probability of exploitation in next 30 days)
- EPSS percentile
- 53.61% vs all CVEs — higher = more likely to be exploited, as of 2026-07-26
NVD / KEV / EPSS data refreshed 2026-07-27 14:03 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2024-2860 - Assigner
- GitHub_M
- Published
- Sep 10, 2024, 3:54:02 PM
- Updated
- Sep 10, 2024, 6:47:22 PM
- EUVD base score (CVSS 3.1)
-
7.5 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EUVD-reported EPSS
- 1.3900
- Vendors
- expressjs
- Products
-
body-parser (< 1.20.3)
- Aliases
-
GHSA-qwcr-r2fm-qrc7
ENISA description: body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-09-25 03:01 UTC (source: CVRF).
- MS CVSS base score
- 7.5 / 10 (temporal 7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - Release
- 2024-Dec
Microsoft remediations / KB articles (3)
- python-tensorboard — Vendor Fix / CBL-Mariner (fixed build 2.16.2-5)
- https://nvd.nist.gov/vuln/detail/CVE-2024-45590 — None Available / python-tensorboard
- reaper — Vendor Fix / CBL-Mariner (fixed build 3.1.1-13)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| expressjs | body-parser |
< 1.20.3 (affected)
|
— |
Affected products — CPE 2.3 (1) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:openjsf:body-parser:*:*:*:*:*:node.js:*:*
Vendor references (2)
References embedded in the original CVE record by the assigning CNA.
MITRE references (2) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
Web references (8)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- None Available msrc
- MSRC update guide: CVE-2024-45590 msrc
- None Available msrc
- https://www.cve.org/CVERecord?id=CVE-2024-45590 rapid7:www.cve.org
- https://attackerkb.com/topics/CVE-2024-45590 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-2860 rapid7:euvd.enisa.europa.eu
- https://jira.atlassian.com/browse/BSERV-20249 rapid7:jira.atlassian.com
- http://cwe.mitre.org/data/definitions/405.html rapid7:cwe.mitre.org
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/expressjs/body-parser/commit/b2695c4450f06ba3b0ccf48d872a229bb41c9bce security-advisories@github.com Patch
- https://github.com/expressjs/body-parser/security/advisories/GHSA-qwcr-r2fm-qrc7 security-advisories@github.com Vendor Advisory
Indicators (1)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| domain |
node.js
|
no local data | 2026-05-18 21:19 UTC |
Remediations (24)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-08-01 02:25 UTC -
web:www.forbes.com
Following the release of a BitLocker zero-day security bypass by a disgruntled hacker, Microsoft has now offered mitigation advice until a patch is available.
2026-08-01 02:25 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-08-01 02:25 UTC -
web:krebsonsecurity.com
Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known "zero-day" or actively exploited ...
2026-08-01 02:25 UTC -
web:krebsonsecurity.com
But with a threat score of 9.8 out of possible 10 and marked "exploitation more likely," CVE -2025-59287 can be exploited without authentication and is an easy " patch now" candidate.
2026-08-01 02:25 UTC -
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-05-22 10:18 UTC -
web:nvd.nist.gov
An official website of the United States government NVD MENU
2026-05-22 10:18 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 10:18 UTC -
web:windowsforum.com
What is CVE - 2024 -43590? CVE - 2024 -43590 refers to a vulnerability in the Visual C++ Redistributable Installer that allows an attacker to gain elevated permissions on a vulnerable system. This flaw could be exploited if a user is tricked into running a malicious installer. Effectively, it poses a risk where standard users inadvertently give potential assailants administrative privileges ...
2026-05-22 10:18 UTC -
web:www.avesnetsec.com
Vulnerability Report for CVE - 2024 -43590 The Microsoft Visual C++ Redistributable Installer is a crucial component of the Microsoft Visual C++ software development environment. It is responsible for installing and managing the necessary runtime components required to run applications developed using Visual C++. However, a recently discovered vulnerability, known as CVE - 2024 -43590, has raised ...
2026-05-22 10:18 UTC -
web:www.cve.org
Vulnerability detail for CVE - 2024 -43590 Product Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
2026-05-22 10:18 UTC -
web:www.linkedin.com
Microsoft Security Response Center has issued an emergency mitigation for a newly disclosed BitLocker bypass vulnerability known as "YellowKey," after security researchers publicly released ...
2026-05-22 10:18 UTC -
web:www.msn.com
Microsoft suggests the threat is being used in phishing attacks against vulnerable systems since successful exploitation requires local access to the PC.
2026-05-22 10:18 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 10:18 UTC -
web:www.cve.news
How the Patch Works The maintainers of body-parser addressed this by adding better checks on input depth and preventing abusive payloads from hogging resources. For more details, check the official GitHub advisory. ` - Use security tools like npm audit to spot vulnerabilities early. References - CVE-2024-45590 NVD - body-parser GitHub Security ...
2026-05-22 02:51 UTC -
web:www.sentinelone.com
CVE-2024-45590 is a denial of service vulnerability in Openjsf Body-parser. Learn about its impact, affected versions, and mitigation methods.
2026-05-22 02:51 UTC -
web:www.cve.org
Vulnerability detail for CVE-2024-45590 Notice: Expanded keyword searching of CVE Records (with limitations) is now available in the search box above. Learn more here.
2026-05-22 02:51 UTC -
web:nvd.nist.gov
This is a potential security issue, you are being redirected to https://nvd.nist.gov
2026-05-22 02:51 UTC -
web:www.cvedetails.com
CVE-2024-45590 : body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor
2026-05-22 02:51 UTC -
web:security.snyk.io
High severity (8.2) Asymmetric Resource Consumption (Amplification) in body-parser | CVE-2024-45590
2026-05-22 02:51 UTC -
web:vulert.com
CVE-2024-45590 : body-parser is vulnerable to a denial of service attack when URL encoding is enabled. Upgrade to version 1.20.3 or apply a temporary workaround to mitigate the vulnerability. Learn more about the impact, fix , and CVSS score.
2026-05-22 02:51 UTC -
web:epatch.pa.gov
Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...
2026-05-22 02:51 UTC -
web:www.tenable.com
body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.
2026-05-22 02:51 UTC -
web:github.com
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
2026-05-22 02:51 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2024-45590.json.
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:expressjs:body-parser:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "body-parser",
"vendor": "expressjs",
"versions": [
{
"lessThan": "1.20.3",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-45590",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-09-10T18:42:41.773305Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-09-10T18:47:22.965Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "body-parser",
"vendor": "expressjs",
"versions": [
{
"status": "affected",
"version": "< 1.20.3"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-405",
"description": "CWE-405: Asymmetric Resource Consumption (Amplification)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-09-10T15:54:02.330Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/expressjs/body-parser/security/advisories/GHSA-qwcr-r2fm-qrc7",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/expressjs/body-parser/security/advisories/GHSA-qwcr-r2fm-qrc7"
},
{
"name": "https://github.com/expressjs/body-parser/commit/b2695c4450f06ba3b0ccf48d872a229bb41c9bce",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/expressjs/body-parser/commit/b2695c4450f06ba3b0ccf48d872a229bb41c9bce"
}
],
"source": {
"advisory": "GHSA-qwcr-r2fm-qrc7",
"discovery": "UNKNOWN"
},
"title": "body-parser vulnerable to denial of service when url encoding is enabled"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2024-45590",
"datePublished": "2024-09-10T15:54:02.330Z",
"dateReserved": "2024-09-02T16:00:02.422Z",
"dateUpdated": "2024-09-10T18:47:22.965Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}