AUGUST 26, 2026
Live Feed
Back to database
Case File

CVE-2026-12590

LOW · CVSS 3.7 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

Versions of body-parser prior to 1.20.6 and 2.3.0 are vulnerable to a denial of service due to improper handling of invalid limit option values, allowing applications to accept excessively large request bodies. This can result in increased memory and CPU usage, potentially leading to service disruption. Developers and system administrators using affected versions should prioritize updating to the patched releases or implementing validation checks for limit values to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-12590
Severity
LOW
CVSS
3.7
EPSS
0.27%

Original NVD Description

Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-parser 1.20.6 and 2.3.0. After the fix, invalid limit values throw a clear error at parser construction time instead of silently disabling enforcement, while null and undefined continue to fall back to the default limit of 100kb. Workarounds: Validate the limit value before passing it to body-parser. For example, parse the value at startup and reject any configuration where the result is null or a non-finite number.

Related CVEs

Other vulnerabilities affecting the same vendor(s)