Qwik's unhandled exception vulnerabilty can cause server crashes from malicious requests
- Severity:
- High
Description
Possibility to craft a request that will crash the Qwik Server in the default configuration.
Recommendation
Update the @builder.io/qwik-city package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.13.0
- Patched version(s): 1.13.0
References
Related Issues
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - CVE-2025-24361
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/webpack-builder - CVE-2025-24361
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/vite-builder - CVE-2025-24360
- string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS) - CVE-2025-45143
You might also like:
- Tags:
- npm
- @builder.io/qwik-city
Anything's wrong? Let us know Last updated on July 09, 2025


