StackRadar

CVE-2025-13466

Medium

Advisory

Published 25 Nov 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 1
affected package

body-parser is vulnerable to denial of service when url encoding is used

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
body-parsernpm2.2.02.2.114
OSV records
GHSA-wqch-xfxh-vrr4

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2025-13466.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
body-parser@2.2.0
2.2.1

Open the chart page →

11,384
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-13466.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
body-parser@2.2.0
2.2.1

Open the chart page →

15,712
stornxstornxVerified publisher1.1.11 of 9See more

stornx stornx 1.1.1

1 of the 9 container images this version deploys carry CVE-2025-13466.

Container imageDigestPackageFixed in
alazidis/stornx:1.1.1602d4f7f090c
body-parser@2.2.0
2.2.1

Open the chart page →

11,574
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2025-13466.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
body-parser@2.2.0
2.2.1
sysnet4admin/colosseum-prm:log5802bfcd7fed
body-parser@2.2.0
2.2.1

Open the chart page →

26,996
mcp-for-argocdchristianhuthVerified publisher2.0.01 of 1See more

mcp-for-argocd christianhuth 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-13466.

Container imageDigestPackageFixed in
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
body-parser@2.2.0
2.2.1

Open the chart page →

1,947
cors-proxycors-proxyVerified publisher1.2.01 of 1See more

cors-proxy cors-proxy 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-13466.

Container imageDigestPackageFixed in
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
body-parser@2.2.0
2.2.1

Open the chart page →

1,598
dapr-agentsdapr-agents-devVerified publisher0.1.51 of 31See more

dapr-agents dapr-agents-dev 0.1.5

1 of the 31 container images this version deploys carry CVE-2025-13466.

Container imageDigestPackageFixed in
ghcr.io/kagent-dev/doc2vec/mcp:1.1.14ace1de323f4a
body-parser@2.2.0
2.2.1

Open the chart page →

22,193
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-13466.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
body-parser@2.2.0
2.2.1

Open the chart page →

2,950
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2025-13466.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
body-parser@2.2.0
2.2.1

Open the chart page →

3,806
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2025-13466.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
body-parser@2.2.0
2.2.1

Open the chart page →

14,809
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-13466.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
body-parser@2.2.0
2.2.1

Open the chart page →

2,318
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2025-13466.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
body-parser@2.2.0
2.2.1

Open the chart page →

2,421
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-13466.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
body-parser@2.2.0
2.2.1

Open the chart page →

1,313
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2025-13466.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
body-parser@2.2.0
2.2.1

Open the chart page →

5,484

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
body-parser@2.2.0
2.2.1
2
alazidis/stornx:1.1.1602d4f7f090c
body-parser@2.2.0
2.2.1
1
luligu/matterbridge:3.0.28f97884bebc2
body-parser@2.2.0
2.2.1
1
sysnet4admin/colosseum-cms:loge74b43c7f492
body-parser@2.2.0
2.2.1
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
body-parser@2.2.0
2.2.1
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
body-parser@2.2.0
2.2.1
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
body-parser@2.2.0
2.2.1
1
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
body-parser@2.2.0
2.2.1
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
body-parser@2.2.0
2.2.1
1
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
body-parser@2.2.0
2.2.1
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
body-parser@2.2.0
2.2.1
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
body-parser@2.2.0
2.2.1
1
ghcr.io/kagent-dev/doc2vec/mcp:1.1.14ace1de323f4a
body-parser@2.2.0
2.2.1
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
body-parser@2.2.0
2.2.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.