Back

MEDIUM

nodejs-qs: Denial-of-Service Memory Exhaustion

Published Oct 19, 2014

Description

The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

Affected products

Remediation

Red Hat statement

This package is not shipped with any versions of Red Hat Enterprise Linux. Red Hat Software Collections Library components shipping in version 2.2 are affected.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 19, 2014
Updated Aug 6, 2024
Reserved Sep 26, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 6, 2014
GHSA-JJV7-QPX3-H62Q