Description
Possibility to craft a request that will crash the Qwik Server in the default configuration.
Recommendation
Update the @builder.io/qwik-city package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.13.0
- Patched version(s): 1.13.0
References
Could your website be exposed too?
SmartScanner can check your website for Qwik's unhandled exception vulnerabilty can cause server crashes from malicious requests and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - CVE-2025-24361
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/webpack-builder - CVE-2025-24361
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/vite-builder - CVE-2025-24360
- string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS) - CVE-2025-45143
You might also like:
See something that needs correcting? Let us knowUpdated July 09, 2025


