CVE-2026-2391
Published Feb 12, 2026### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memor…
- evidence mentions
- 2
- Buzz score
- 16.0