Description
Versions prior to 1.0.0 of qs are affected by a denial of service vulnerability that results from excessive recursion in parsing a deeply nested JSON string.
Recommendation
Update the qs package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.0
- Patched version(s): 1.0.0
References
Related Issues
- Denial-of-Service Memory Exhaustion in qs - CVE-2014-7191
- Regular Expression Denial of Service in validator - CVE-2014-8882
- Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input - CVE-2026-33891
- qs's arrayLimit bypass in comma parsing allows denial of service - CVE-2026-2391
- Tags:
- npm
- qs
Anything's wrong? Let us know Last updated on January 09, 2023