Your message dated Thu, 30 Jul 2026 13:06:00 +0000
with message-id <[email protected]>
and subject line Bug#1143074: fixed in node-body-parser 2.3.0+~1.19.6-1
has caused the Debian Bug report #1143074,
regarding node-body-parser: CVE-2026-12590
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1143074: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143074
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-body-parser
Version: 2.2.2+~1.19.6-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for node-body-parser.
CVE-2026-12590[0]:
| Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0
| (2.x line), when the parser is configured with an invalid limit
| option value such as an unparseable string or NaN, bytes.parse
| returns null and the request body size check is silently skipped.
| Applications that rely on limit as their primary safeguard against
| oversized request bodies will accept arbitrarily large payloads,
| leading to excessive memory and CPU usage and denial of service.
| Patches: This issue is fixed in body-parser 1.20.6 and 2.3.0. After
| the fix, invalid limit values throw a clear error at parser
| construction time instead of silently disabling enforcement, while
| null and undefined continue to fall back to the default limit of
| 100kb. Workarounds: Validate the limit value before passing it to
| body-parser. For example, parse the value at startup and reject any
| configuration where the result is null or a non-finite number.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-12590
https://www.cve.org/CVERecord?id=CVE-2026-12590
[1]
https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6
[2] https://github.com/expressjs/body-parser/pull/698
[3]
https://github.com/expressjs/body-parser/commit/2322e111cc321413ec2b7b76d01be533d3de9d7d
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: node-body-parser
Source-Version: 2.3.0+~1.19.6-1
Done: Xavier Guimard <[email protected]>
We believe that the bug you reported is fixed in the latest version of
node-body-parser, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-body-parser package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 30 Jul 2026 14:38:22 +0200
Source: node-body-parser
Architecture: source
Version: 2.3.0+~1.19.6-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1143074
Changes:
node-body-parser (2.3.0+~1.19.6-1) unstable; urgency=medium
.
* Team upload
* Declare compliance with policy 4.7.4
* Drop "Priority: optional"
* New upstream version (Closes: #1143074, CVE-2026-12590)
Checksums-Sha1:
5806d4c7bfef9d3e583df77e39452739cb576671 2747
node-body-parser_2.3.0+~1.19.6-1.dsc
1859bebb8fd7dac9918a45d54c1971ab8b5af474 2945
node-body-parser_2.3.0+~1.19.6.orig-types-body-parser.tar.gz
41ffd487f8a876dc304b89ef974c99cf16438733 29818
node-body-parser_2.3.0+~1.19.6.orig.tar.gz
6c811a7b958971f18760c5f7d17c422d24ffa4e5 3916
node-body-parser_2.3.0+~1.19.6-1.debian.tar.xz
Checksums-Sha256:
a94df2a24eeff9bec51a0877577f46270c11ca25c99d0b9a4d5cde92e08bb556 2747
node-body-parser_2.3.0+~1.19.6-1.dsc
640c729c03c2527aca389e1e134d342a5ccee6b394b700e297141f580fe89f8a 2945
node-body-parser_2.3.0+~1.19.6.orig-types-body-parser.tar.gz
3d8f17b56be2a3c7d48058bbe6a01ee628e38f431f9d44b7bc6d83d9542772d6 29818
node-body-parser_2.3.0+~1.19.6.orig.tar.gz
150780a7582702d1054c473e181936f51236f3069fcac26b30d4dc0684b2916c 3916
node-body-parser_2.3.0+~1.19.6-1.debian.tar.xz
Files:
689ae61fa0ee0b1962e509e084c96700 2747 javascript optional
node-body-parser_2.3.0+~1.19.6-1.dsc
ecea4b2ead546efcfaa132b3bdf8c290 2945 javascript optional
node-body-parser_2.3.0+~1.19.6.orig-types-body-parser.tar.gz
af368593e076b5070de8de845390e056 29818 javascript optional
node-body-parser_2.3.0+~1.19.6.orig.tar.gz
bba4128154419340bf9153bc1457ea11 3916 javascript optional
node-body-parser_2.3.0+~1.19.6-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmprRt0ACgkQ9tdMp8mZ
7umoRQ/9Ev29ln4DZ7cnWf5Pm9/dCV5G9+znp5g2DmjFiXfo1JR/n3tjbpv/zAdS
MiIiSDy5FV+p3kFAc79TwPTHcHANr8EbCtnWYB6sw7dylQe9p0LT6cL6fohJfHCn
sxx5t21A++9Z0cIxZwynTkBAIePizS7r6AGyn6JuPyhNoLWjlPRVonhq5+fjj2sE
Ys4tDe3hWOdBtyKAvE/GcC4/8bd/6QXOWCnDBdSdG35IIWChYi8PpJkIAH9vx+eD
RF7+h02UdvT4g/9001R1hh1wdDbJsizD5BA7O4bUP14VoC4GfcNb+rX9JzDQas75
Oc90QYwKcRAvPlYtzAr76anLrVLoR7evoUBsS59cNwgRnfoQJ1AMDeKqhjCA4jBc
CydipuJ+qsyZqBrEIp/tL3t0ShGzKiEWhASeOAyOz5cjF70n6NXZtPBoyRmLPdMr
Ntq9vumS6L3phWOIURF4ohYAs1DucG6nv39T9umTXyoJHDt37H9wPqZeYqt9qDHi
Lqp8/ntK8oWneEWMECSVdt420v3Pxjs6N9E7BxtPNK5qhKNa9KdVc5ernMgUjtFu
DXh4+jNlAZNHPTDJvObxhNLRVmIDahtfRT4uAaV69miFmB5awKacnDOgn05pEVf2
q/UvwOQt2AGXAK7HFMh0f20EITKeiPKD/IHsUtHNU52V3MvtBG0=
=SUXr
-----END PGP SIGNATURE-----
pgp9aS5k5pRke.pgp
Description: PGP signature
--- End Message ---
--
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel