QS Project / QS
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-2391 | qs's arrayLimit bypass in comma parsing allows denial of service | MEDIUM | 6.3 | Feb 12, 2026 |
| CVE-2025-15284 | arrayLimit bypass in bracket notation allows DoS via memory exhaustion | MEDIUM | 6.3 | Dec 29, 2025 |
| CVE-2022-24999 | express: "qs" prototype poisoning causes the hang of the node process | HIGH | 7.5 | Nov 26, 2022 |
| CVE-2014-10064 | The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will bl… | HIGH | 7.5 | May 31, 2018 |
| CVE-2017-1000048 | nodejs-qs: Prototype override protection bypass | HIGH | 7.5 | Jul 13, 2017 |
Showing 1 to 5 of 5 CVEs