nodejs-qs: Denial-of-Service Memory Exhaustion
Published Oct 19, 2014
5.0
MEDIUMCVSS 2.0
EPSS 8.31%
Description
The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.
Affected products
No data.
No data.
Red Hat Software Collections for Red Hat Enterprise Linux 6
nodejs010-node-gyp-0:3.2.0-3.el6
Fixed · RHSA-2016:1380
Red Hat Software Collections for Red Hat Enterprise Linux 6
nodejs010-nodejs-qs-0:0.6.5-5.el6
Fixed · RHSA-2016:1380
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS
nodejs010-node-gyp-0:3.2.0-3.el6
Fixed · RHSA-2016:1380
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS
nodejs010-nodejs-qs-0:0.6.5-5.el6
Fixed · RHSA-2016:1380
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
nodejs010-node-gyp-0:3.2.0-3.el6
Fixed · RHSA-2016:1380
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
nodejs010-nodejs-qs-0:0.6.5-5.el6
Fixed · RHSA-2016:1380
Red Hat Software Collections for Red Hat Enterprise Linux 7
nodejs010-node-gyp-0:3.2.0-3.el7
Fixed · RHSA-2016:1380
Red Hat Software Collections for Red Hat Enterprise Linux 7
nodejs010-nodejs-qs-0:0.6.5-5.el7
Fixed · RHSA-2016:1380
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS
nodejs010-node-gyp-0:3.2.0-3.el7
Fixed · RHSA-2016:1380
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS
nodejs010-nodejs-qs-0:0.6.5-5.el7
Fixed · RHSA-2016:1380
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
nodejs010-node-gyp-0:3.2.0-3.el7
Fixed · RHSA-2016:1380
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
nodejs010-nodejs-qs-0:0.6.5-5.el7
Fixed · RHSA-2016:1380
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | nodejs010-node-gyp-0:3.2.0-3.el6 | Fixed | RHSA-2016:1380 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | nodejs010-nodejs-qs-0:0.6.5-5.el6 | Fixed | RHSA-2016:1380 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | nodejs010-node-gyp-0:3.2.0-3.el6 | Fixed | RHSA-2016:1380 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | nodejs010-nodejs-qs-0:0.6.5-5.el6 | Fixed | RHSA-2016:1380 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | nodejs010-node-gyp-0:3.2.0-3.el6 | Fixed | RHSA-2016:1380 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | nodejs010-nodejs-qs-0:0.6.5-5.el6 | Fixed | RHSA-2016:1380 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | nodejs010-node-gyp-0:3.2.0-3.el7 | Fixed | RHSA-2016:1380 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | nodejs010-nodejs-qs-0:0.6.5-5.el7 | Fixed | RHSA-2016:1380 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | nodejs010-node-gyp-0:3.2.0-3.el7 | Fixed | RHSA-2016:1380 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | nodejs010-nodejs-qs-0:0.6.5-5.el7 | Fixed | RHSA-2016:1380 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | nodejs010-node-gyp-0:3.2.0-3.el7 | Fixed | RHSA-2016:1380 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | nodejs010-nodejs-qs-0:0.6.5-5.el7 | Fixed | RHSA-2016:1380 |
qs
npm
Introduced 0 Fixed 1.0.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | qs | 0 | 1.0.0 |
Remediation
Red Hat statement
This package is not shipped with any versions of Red Hat Enterprise Linux. Red Hat Software Collections Library components shipping in version 2.2 are affected.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.31% (0.08309) | 94.77th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.31% (0.08309) | 94.20th | v5 (v2026.06.15) |
| Mar 8, 2026 | 0.69% (0.00690) | 71.48th | v4 (v2025.03.14) |
| Sep 13, 2025 | 3.00% (0.03001) | 86.07th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.22% (0.01222) | 77.25th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.17% (0.03171) | 78.11th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.22% (0.01222) | 77.72th | v4 (v2025.03.14) |
| Dec 12, 2024 | 5.33% (0.05333) | 93.38th | v3 (v2023.03.01) |
| May 31, 2024 | 5.33% (0.05333) | 93.08th | v3 (v2023.03.01) |
| Apr 14, 2024 | 5.99% (0.05993) | 93.36th | v3 (v2023.03.01) |
| Mar 7, 2023 | 5.96% (0.05956) | 92.29th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.17% (0.02172) | 80.77th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.17% (0.02172) | 78.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.17% (0.02172) | 57.73th | v2 (v2022.01.01) |
References (16)
- http://secunia.com/advisories/60026 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62170 third-party-advisoryx_refsource_SECUNIA
- http://www-01.ibm.com/support/docview.wss?uid=swg21685987 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21687263 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21687928 x_refsource_CONFIRM
- https://access.redhat.com/errata/RHSA-2016:1380 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2014-7191 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1146054 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96729 vdb-entryx_refsource_XF
- https://github.com/advisories/GHSA-jjv7-qpx3-h62q Advisory
- https://github.com/raymondfeng/node-querystring/commit/43a604b7847e56bba49d0ce3e222fe89569354d8 x_refsource_CONFIRMPatch
- https://github.com/visionmedia/node-querystring/issues/104 x_refsource_CONFIRM
- https://nodesecurity.io/advisories/qs_dos_memory_exhaustion x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2014-7191
- https://www.cve.org/CVERecord?id=CVE-2014-7191
- https://www.npmjs.com/advisories/29
Change history (0)
No recorded changes yet.