Uh oh!
There was an error while loading. Please reload this page.
[GHSA-wqch-xfxh-vrr4] body-parser is vulnerable to denial of service when url encoding is used - #6468
Conversation
github
commented
Nov 25, 2025
Hi there @UlisesGascon! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
jonchurch
commented
Nov 25, 2025
What's the github comment on about? but @UlisesGascon originally created the GHSA, im also an owner of the repo but clearly not him. I updated the CVSS string because the one that was already populated was saying it was invalid? The repo level GHSA was using CVSS 3.1 so I lifted that string from there for here and it satisfied the form's validation |
jonchurch
commented
Nov 25, 2025
closing in favor of #6470 |
Updates
Comments
The version range is inaccurate, it needs to be exactly 2.2.0 as per the body of the report