s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2024-45590

📛 CVE Title

body-parser vulnerable to denial of service when url encoding is enabled

Description

body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.

Overview

State
PUBLISHED
Assigner (CNA)
GitHub_M
CVSS severity
HIGH
CVSS score
CVSS 7.5 / 10 7.5 7.5 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Effective score
7.5 / 10 HIGH source: CNA overview
MSRC score
7.5 / 10 HIGH
CWE(s)
CWE-405
Reserved
2024-09-02
Published
2024-09-10 17:54 UTC
Last updated
2024-09-10 20:47 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/45xxx/CVE-2024-45590.json
Linked Threat
CVE-2024-45590 — body-parser vulnerable to denial of service when url encoding is enabled

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2024-09-10 16:15:21 UTC
NVD last modified
2026-06-17 07:54:31 UTC
NVD CVSS v3.1
CVSS 7.5 / 10 7.5 7.5 / 10 HIGH source: security-advisories@github.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability subscore
3.9 / 10
Impact subscore
3.6 / 10
EPSS score
0.0082 (probability of exploitation in next 30 days)
EPSS percentile
53.61% vs all CVEs — higher = more likely to be exploited, as of 2026-07-26

NVD / KEV / EPSS data refreshed 2026-07-27 14:03 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2024-2860
Assigner
GitHub_M
Published
Sep 10, 2024, 3:54:02 PM
Updated
Sep 10, 2024, 6:47:22 PM
EUVD base score (CVSS 3.1)
7.5 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EUVD-reported EPSS
1.3900
Vendors
expressjs
Products
body-parser (< 1.20.3)
Aliases
GHSA-qwcr-r2fm-qrc7

ENISA description: body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.

EUVD references (2)

Microsoft Security Response Center MSRC

Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-09-25 03:01 UTC (source: CVRF).

MS CVSS base score
7.5 / 10 (temporal 7.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Release
2024-Dec
Microsoft remediations / KB articles (3)

Affected products (1)

VendorProductVersionsPlatforms
expressjs body-parser < 1.20.3 (affected) —

Affected products — CPE 2.3 (1) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:a:openjsf:body-parser:*:*:*:*:*:node.js:*:*

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

MITRE references (2) cveawg.mitre.org

Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.

Web references (8)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (2)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (1)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
domain node.js no local data 2026-05-18 21:19 UTC

Flagged vendors

    Remediations (24)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:msrc.microsoft.com

      The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.

      2026-08-01 02:25 UTC
    • web:www.forbes.com

      Following the release of a BitLocker zero-day security bypass by a disgruntled hacker, Microsoft has now offered mitigation advice until a patch is available.

      2026-08-01 02:25 UTC
    • web:www.computerworld.com

      Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...

      2026-08-01 02:25 UTC
    • web:krebsonsecurity.com

      Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known "zero-day" or actively exploited ...

      2026-08-01 02:25 UTC
    • web:krebsonsecurity.com

      But with a threat score of 9.8 out of possible 10 and marked "exploitation more likely," CVE -2025-59287 can be exploited without authentication and is an easy " patch now" candidate.

      2026-08-01 02:25 UTC
    • web:cybersecuritynews.com

      Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.

      2026-05-22 10:18 UTC
    • web:nvd.nist.gov

      An official website of the United States government NVD MENU

      2026-05-22 10:18 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-05-22 10:18 UTC
    • web:windowsforum.com

      What is CVE - 2024 -43590? CVE - 2024 -43590 refers to a vulnerability in the Visual C++ Redistributable Installer that allows an attacker to gain elevated permissions on a vulnerable system. This flaw could be exploited if a user is tricked into running a malicious installer. Effectively, it poses a risk where standard users inadvertently give potential assailants administrative privileges ...

      2026-05-22 10:18 UTC
    • web:www.avesnetsec.com

      Vulnerability Report for CVE - 2024 -43590 The Microsoft Visual C++ Redistributable Installer is a crucial component of the Microsoft Visual C++ software development environment. It is responsible for installing and managing the necessary runtime components required to run applications developed using Visual C++. However, a recently discovered vulnerability, known as CVE - 2024 -43590, has raised ...

      2026-05-22 10:18 UTC
    • web:www.cve.org

      Vulnerability detail for CVE - 2024 -43590 Product Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)

      2026-05-22 10:18 UTC
    • web:www.linkedin.com

      Microsoft Security Response Center has issued an emergency mitigation for a newly disclosed BitLocker bypass vulnerability known as "YellowKey," after security researchers publicly released ...

      2026-05-22 10:18 UTC
    • web:www.msn.com

      Microsoft suggests the threat is being used in phishing attacks against vulnerable systems since successful exploitation requires local access to the PC.

      2026-05-22 10:18 UTC
    • web:www.oracle.com

      This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.

      2026-05-22 10:18 UTC
    • web:www.cve.news

      How the Patch Works The maintainers of body-parser addressed this by adding better checks on input depth and preventing abusive payloads from hogging resources. For more details, check the official GitHub advisory. ` - Use security tools like npm audit to spot vulnerabilities early. References - CVE-2024-45590 NVD - body-parser GitHub Security ...

      2026-05-22 02:51 UTC
    • web:www.sentinelone.com

      CVE-2024-45590 is a denial of service vulnerability in Openjsf Body-parser. Learn about its impact, affected versions, and mitigation methods.

      2026-05-22 02:51 UTC
    • web:www.cve.org

      Vulnerability detail for CVE-2024-45590 Notice: Expanded keyword searching of CVE Records (with limitations) is now available in the search box above. Learn more here.

      2026-05-22 02:51 UTC
    • web:nvd.nist.gov

      This is a potential security issue, you are being redirected to https://nvd.nist.gov

      2026-05-22 02:51 UTC
    • web:www.cvedetails.com

      CVE-2024-45590 : body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor

      2026-05-22 02:51 UTC
    • web:security.snyk.io

      High severity (8.2) Asymmetric Resource Consumption (Amplification) in body-parser | CVE-2024-45590

      2026-05-22 02:51 UTC
    • web:vulert.com

      CVE-2024-45590 : body-parser is vulnerable to a denial of service attack when URL encoding is enabled. Upgrade to version 1.20.3 or apply a temporary workaround to mitigate the vulnerability. Learn more about the impact, fix , and CVSS score.

      2026-05-22 02:51 UTC
    • web:epatch.pa.gov

      Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...

      2026-05-22 02:51 UTC
    • web:www.tenable.com

      body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.

      2026-05-22 02:51 UTC
    • web:github.com

      GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

      2026-05-22 02:51 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2024-45590.json.

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:expressjs:body-parser:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "body-parser",
                "vendor": "expressjs",
                "versions": [
                  {
                    "lessThan": "1.20.3",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-45590",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T18:42:41.773305Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-10T18:47:22.965Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "body-parser",
              "vendor": "expressjs",
              "versions": [
                {
                  "status": "affected",
                  "version": "< 1.20.3"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-405",
                  "description": "CWE-405: Asymmetric Resource Consumption (Amplification)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-10T15:54:02.330Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/expressjs/body-parser/security/advisories/GHSA-qwcr-r2fm-qrc7",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/expressjs/body-parser/security/advisories/GHSA-qwcr-r2fm-qrc7"
            },
            {
              "name": "https://github.com/expressjs/body-parser/commit/b2695c4450f06ba3b0ccf48d872a229bb41c9bce",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/expressjs/body-parser/commit/b2695c4450f06ba3b0ccf48d872a229bb41c9bce"
            }
          ],
          "source": {
            "advisory": "GHSA-qwcr-r2fm-qrc7",
            "discovery": "UNKNOWN"
          },
          "title": "body-parser vulnerable to denial of service when url encoding is enabled"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2024-45590",
        "datePublished": "2024-09-10T15:54:02.330Z",
        "dateReserved": "2024-09-02T16:00:02.422Z",
        "dateUpdated": "2024-09-10T18:47:22.965Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }