{"id":"GHSA-qgc4-8p88-4w7m","summary":"Servify-express rate limit issue","details":"### Impact\nThe Express server uses `express.json()` without a size limit, which can allow attackers to send extremely large request bodies. This may lead to excessive memory usage, degraded performance, or process crashes, resulting in a Denial of Service (DoS). Any application using the JSON parser without limits and exposed to untrusted clients is affected.\n\n### Patches\nThis issue is not a flaw in Express itself but in configuration. Users should set a request-size limit when enabling the JSON body parser. For example:\n`app.use(express.json({ limit: \"100kb\" }));`\n\n### Workarounds\nUsers can mitigate the issue without upgrading by:\n- Adding a `limit` option to the JSON parser\n- Implementing rate limiting at the application or reverse-proxy level\n- Rejecting unusually large requests before parsing\n- Using a reverse proxy (such as NGINX) to enforce maximum request body sizes","aliases":["CVE-2025-67731"],"modified":"2026-09-10T03:50:32.066751268Z","published":"2025-12-11T18:36:54Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-12-11T18:36:54Z","nvd_published_at":"2025-12-12T08:15:48Z","cwe_ids":["CWE-770"]},"references":[{"type":"WEB","url":"https://github.com/Aarondoran/servify-express/security/advisories/GHSA-qgc4-8p88-4w7m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67731"},{"type":"WEB","url":"https://github.com/Aarondoran/servify-express/commit/197d848e5450bf85b0dd19ef8c2aa4ba96192300"},{"type":"WEB","url":"https://github.com/Aarondoran/servify-express/commit/8dff7f56504b356278d849734ef2050e5cd23b61"},{"type":"PACKAGE","url":"https://github.com/Aarondoran/servify-express"},{"type":"WEB","url":"https://github.com/Aarondoran/servify-express/releases/tag/V1.2"}],"affected":[{"package":{"name":"servify-express","ecosystem":"npm","purl":"pkg:npm/servify-express"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-qgc4-8p88-4w7m/GHSA-qgc4-8p88-4w7m.json","last_known_affected_version_range":"\u003c= 1.1"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}