Vulnerabilities/

Denial-of-Service Memory Exhaustion in qs

Severity:
High

Description

Versions prior to 1.0 of qs are affected by a denial of service condition. This condition is triggered by parsing a crafted string that deserializes into very large sparse arrays, resulting in the process running out of memory and eventually crashing.

Recommendation

Update the qs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
qs
Anything's wrong? Let us know Last updated on April 11, 2023

This issue is available in SmartScanner Professional

See Pricing