Skip to main content

Vendor/product archive

qs_project / qs CVEs

Beta · best-effort

5 CVEs tagged to qs_project / qs0 Critical, 3 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-2391

Published Feb 12, 2026

### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memor…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-15284

Published Dec 29, 2025

Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimit option in qs did not enforce limits for br…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2014-10064

Published May 31, 2018

The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000048

Published Jul 17, 2017

the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framewor…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1