NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #305 most downloaded on npm
Node.js body parsing middleware
Last release 27 days ago
08 Sep 2026
Release timing varies
gaps range from 3 weeks to 1.5 years
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
85 releases · first in 2014
Security fix for CVE-2026-12590 ( GHSA-v422-hmwv-36x6 )
Full Changelog: v2.2.2...v2.3.0
One column per quarter.
docs: update README links by @efekrskl in #673
Full Changelog: v2.2.1...v2.2.2
Security fix for CVE-2025-13466 ( GHSA-wqch-xfxh-vrr4 )
Full Changelog: v2.2.0...v2.2.1
test: remove --bail from test script by @Phillip9587 in #583
--bail from test script by @Phillip9587 in #583lcovonly reporter for the test-ci script by @Phillip9587 in #584Full Changelog: v2.1.0...v2.2.0
fix: update package.json engines field to reflect minimum supported node version by @Phillip9587 in #541
methods by @Phillip9587 in #548safe-buffer by @Phillip9587 in #547type-is to v2.0.0 by @Phillip9587 in #571destroy by @Phillip9587 in #570debug to ^4.4.0 by @Phillip9587 in #579Full Changelog: 2.0.1...v2.1.0
fix: update package.json engines field to reflect minimum supported node version by @Phillip9587 in #541
methods by @Phillip9587 in #548Full Changelog: 2.0.1...2.0.2
Fix defaulting to extended url parsing by @blakeembrey in #536
Full Changelog: 2.0.0...2.0.1
Breaking Change: Node.js 18 is the minimum supported version
raw-body@3 by @wesleytodd in https://github.com/expressjs/body-parser/pull/529Full Changelog: https://github.com/expressjs/body-parser/compare/1.20.2...2.0.0
Remove deprecated bodyParser() combination middleware
This incorporates all changes after 1.19.1 up to 1.20.2.
bodyParser() combination middlewareDEBUG_HIDE_DATE environment variableDEBUG_FD environment variable supportreq.body is no longer always initialized to {}
req.body is no longer always initialized to {}
undefined unless a body is parsedurlencoded parser now defaults extended to falseon-finished to determine when body readSame code base as 1.20.7 . This was created to test the new release process.
Same code base as 1.20.7. This was created to test the new release process.
Full Changelog: 1.20.7...1.20.8
Security fix for CVE-2026-12590 ( GHSA-v422-hmwv-36x6 )
Full Changelog: 1.20.5...1.20.6
The reason for this release is a fix to the extended urlencoded parser returning objects instead of arrays for large array inputs (> 100) on qs@6.14.2
The reason for this release is a fix to the extended urlencoded parser returning objects instead of arrays for large array inputs (> 100) on qs@6.14.2+. (https://github.com/expressjs/body-parser/pull/716)
Special thanks to triager @krzysdz for keeping this on our radar and effectively triaging the specific issue!
Full Changelog: https://github.com/expressjs/body-parser/compare/1.20.4...1.20.5
The reason for this release is a fix to the extended urlencoded parser returning objects instead of arrays for large array inputs (> 100) on qs@6.14.2+. (#716)
Special thanks to triager @krzysdz for keeping this on our radar and effectively triaging the specific issue!
Full Changelog: 1.20.4...1.20.5
Remove redundant depth check by @blakeembrey in #538
Full Changelog: 1.20.3...1.20.4
add depth option to customize the depth level in the parser
depth option to customize the depth level in the parserdepth level for parsing URL-encoded data is now 32 (previously was Infinity). DocumentationFull Changelog: https://github.com/expressjs/body-parser/compare/1.20.2...1.20.3
Fix strict json error message on Node.js 19+
perf: remove unnecessary object clone
Fix error message for json parse whitespace in strict
strict
eval usage with Function constructorprocess to check for listeners* deps: bytes@3.1.2 * deps: qs@6.9.7 * Fix handling of __proto__ keys * deps: raw-body@2.4.3 - deps: bytes@3.1.2
__proto__ keys* deps: bytes@3.1.1 * deps: http-errors@1.8.1 - deps: inherits@2.0.4 - deps: toidentifier@1.0.1 - deps: setprototypeof@1.2.0 * deps: qs@6.9.6 * deps:
Set constructor name when possible
pb) supportthrow on invalid typeFix deprecation warnings on Node.js 10+
perf: remove argument reassignment
perf: remove argument reassignment
Fix JSON strict violation error to match native parse error
body property on verify errorstype property on all generated errorshttp-errors to set status code on errorsBuffer loadinghttp-errors for standard emitted errorsthrow when missing charset* deps: debug@2.6.7 - Fix DEBUG_MAX_ARRAY_LENGTH - deps: ms@2.0.0 * deps: type-is@~1.6.15 - deps: mime-types@~2.1.15
DEBUG_MAX_ARRAY_LENGTHFix regression parsing keys starting with [
[Make message property enumerable for HttpErrors
message property enumerable for HttpErrorsFix deprecation messages in WebStorm and other editors
DEBUG_FD set to 1 or 2Deprecated DEBUG_FD environment variable
DEBUG_FD environment variableUse setprototypeof module to replace __proto__ setting
setprototypeof module to replace __proto__ settingDrop partial bytes on all parsed units
Add HttpError export, for err instanceof createError.HttpError
HttpError export, for err instanceof createError.HttpError- deps: bytes@2.2.0 - deps: iconv-lite@0.4.13 - deps: qs@5.2.0 - deps: raw-body@~2.1.5 - deps: bytes@2.2.0 - deps: iconv-lite@0.4.13 - deps: type-is@~
Fix issue where invalid charset results in 400 when verify used
verify usediconv-liteFix JSON strict parse error to match syntax errors
require analysis in urlencoded parser- deps: type-is@~1.6.6 - deps: mime-types@~2.1.4
Fix dropping parameters like hasOwnProperty
hasOwnPropertymakeErrorDowngraded from 3.1.0 because of user-visible incompatibilities
Add statusCode property on Errors, in addition to status
statusCode property on Errors, in addition to statustype default to application/json for JSON parsertype default to application/x-www-form-urlencoded for urlencoded parserrequire analysishttp-errors module to generate errorsCONNECT requestsUpgrade requestshasOwnPropertynull prototypeunpipe module for unpiping requestsFix allowing parameters like constructor
constructorSlight efficiency improvement when not debugging
Fix error when parameter hasOwnProperty is present
hasOwnProperty is presentFix high intensity foreground color for bold
accept a function for the type option
debug messagestype optioncontent-type to parse Content-Type headersObject.prototypehasBody Transfer-Encoding check*/*)make internal extended: true depth limit infinity
extended: true depth limit infinityFix rare aliases of single-byte encodings
- deps: on-finished@~2.2.0 - deps: type-is@~1.5.5 - deps: mime-types@~2.0.7
make internal extended: true array limit dynamic
extended: true array limit dynamicFix Windows-31J and X-SJIS encoding support
arrayLimit behaviorFix parsing of mixed objects and values
Fix handling of pipelined requests
include the charset in "unsupported charset" error message
fix content encoding to be case-insensitive
Fix issue with object keys starting with numbers truncated
Nothing published for this version
- deps: media-typer@0.3.0 - deps: type-is@~1.5.1
make empty-body-handling consistent between chunked requests
json produces {}raw produces new Buffer(0)text produces ''urlencoded produces {}hasbody to be true for content-length: 0add parameterLimit option to urlencoded parser
parameterLimit option to urlencoded parserurlencoded extended array limit to 100parameterLimit in urlencoded- deps: qs@2.2.2 - Remove unnecessary cloning
Your coding agent can read these notes before it upgrades. Set up the MCP server →