---
id: CVE-2025-67731
title: >-
  Servify Express is a Node.js package to start an Express server and log the
  port it's running on
summary: >-
  Servify Express is a Node.js package to start an Express server and log the
  port it's running on. Prior to 1.2, the Express server used express.json()
  without a size limit, which could allow attackers to send extremely large
  request bodi…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: servify-express.js
product: servify_express
affected:
  - servify_express < 1.2
patched:
  - servify_express 1.2
published: '2025-12-12'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67731'
references:
  - url: >-
      https://github.com/Aarondoran/servify-express/commit/8dff7f56504b356278d849734ef2050e5cd23b61
    label: security-advisories@github.com
  - url: 'https://github.com/Aarondoran/servify-express/releases/tag/V1.2'
    label: security-advisories@github.com
  - url: >-
      https://github.com/Aarondoran/servify-express/security/advisories/GHSA-qgc4-8p88-4w7m
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00403
epssPercentile: 0.32302
ingestedAt: '2026-10-07T20:46:46.897Z'
---

## Overview

Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Express server used express.json() without a size limit, which could allow attackers to send extremely large request bodies. This can cause excessive memory usage, degraded performance, or process crashes, resulting in a Denial of Service (DoS). Any application using the JSON parser without limits and exposed to untrusted clients is affected. The issue is not a flaw in Express itself, but in configuration. This issue is fixed in version 1.2. To work around, consider adding a limit option to the JSON parser, rate limiting at the application or reverse-proxy level, rejecting unusually large requests before parsing, or using a reverse proxy (such as NGINX) to enforce maximum request body sizes.

## Affected

- `servify_express < 1.2`

## Remediation

Upgrade past the affected range:

- `servify_express 1.2`
