{"id":"CVE-2025-67731","title":"Servify Express is a Node.js package to start an Express server and log the port it's running on","summary":"Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Express server used express.json() without a size limit, which could allow attackers to send extremely large request bodi…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400"],"vendor":"servify-express.js","product":"servify_express","affected":["servify_express < 1.2"],"patched":["servify_express 1.2"],"published":"2025-12-12","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:10:01.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-67731","references":[{"url":"https://github.com/Aarondoran/servify-express/commit/8dff7f56504b356278d849734ef2050e5cd23b61","label":"security-advisories@github.com"},{"url":"https://github.com/Aarondoran/servify-express/releases/tag/V1.2","label":"security-advisories@github.com"},{"url":"https://github.com/Aarondoran/servify-express/security/advisories/GHSA-qgc4-8p88-4w7m","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00403,"epssPercentile":0.32302,"ingestedAt":"2026-10-07T20:46:46.897Z","slug":"CVE-2025-67731","body":"## Overview\n\nServify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Express server used express.json() without a size limit, which could allow attackers to send extremely large request bodies. This can cause excessive memory usage, degraded performance, or process crashes, resulting in a Denial of Service (DoS). Any application using the JSON parser without limits and exposed to untrusted clients is affected. The issue is not a flaw in Express itself, but in configuration. This issue is fixed in version 1.2. To work around, consider adding a limit option to the JSON parser, rate limiting at the application or reverse-proxy level, rejecting unusually large requests before parsing, or using a reverse proxy (such as NGINX) to enforce maximum request body sizes.\n\n## Affected\n\n- `servify_express < 1.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `servify_express 1.2`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}