qs
npm7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting qspage 1 of 1
- CVE-2014-10064HIGHCVSS 7.5EG 7.5✓ Fixed in 1.0.02018-05-31
The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of time. An attacker could leverage this to …
- CVE-2014-7191NONECVSS 0.0EG 0.0✓ Fixed in 1.0.02014-10-19
The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.
- CVE-2017-1000048HIGHCVSS 7.5EG 7.5✓ Fixed in 6.3.22017-07-17
the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.
- CVE-2022-24999HIGHCVSS 7.5EG 7.5✓ Fixed in 6.2.42022-11-26
qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated re…
- CVE-2025-15284LOWCVSS 3.7EG 3.7✓ Fixed in 6.14.12025-12-29
Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[…
- CVE-2026-2391LOWCVSS 3.7EG 3.7✓ Fixed in 6.14.22026-02-12
### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcemen…
- CVE-2026-8723MEDIUMCVSS 5.3EG 5.3✓ Fixed in 6.15.22026-05-17
### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related option…
Check whether qs is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for qs CVEs against the assets you own.
Start Free Scan →