Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2230377
AlmaLinux
5964
Alpaquita
16124
Alpine
4635
Android
3677
Azure Linux
17766
BellSoft Hardened Containers
762
Bitnami
9476
Chainguard
1042229
CleanStart
5179
CRAN
14
crates.io
2746
Debian
68788
Echo
7618
GHC
3
GIT
108628
GitHub Actions
55
Go
9254
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6233
Maven
7048
MinimOS
147097
npm
229049
NuGet
1869
opam
29
openEuler
8900
openSUSE
14509
OSS-Fuzz
4015
Packagist
7100
Pub
11
PyPI
25414
Red Hat
23452
Rocky Linux
4328
Root
19620
RubyGems
5326
SUSE
23401
SwiftURL
60
TuxCare
9722
Ubuntu
65803
VSCode
21
Wolfi
292367
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-x5fp-wj9c-mxmx
npm/qs
qs array-limit bypass via bracket-key comma parsing
02 Sep
Fix available
Severity - 6.3 (Medium)
GHSA-4mjr-xmp4-gh2g
npm/qs
qs: Denial of Service via Attacker Controlled isBuffer
02 Sep
Fix available
Severity - 6.3 (Medium)
GHSA-q8mj-m7cp-5q26
npm/qs
qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set
22 May
Fix available
Severity - 6.3 (Medium)
GHSA-w7fw-mjwx-w883
npm/qs
qs's arrayLimit bypass in comma parsing allows denial of service
12 Feb
Fix available
Severity - 3.7 (Low)
MAL-2026-528
npm/@shije/new-qs
Malicious code in @shije/new-qs (npm)
27 Jan
No fix available
GHSA-6rw7-vpxm-498p
npm/qs
qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion
30 Dec 2025
Fix available
Severity - 6.3 (Medium)
MAL-2025-13485
npm/@zalastax/nolb-qs
Malicious code in @zalastax/nolb-qs (npm)
14 Aug 2025
No fix available
MAL-2025-31049
npm/qs-test-pro
Malicious code in qs-test-pro (npm)
14 Aug 2025
No fix available
MAL-2025-2892
npm/qs-appbar-menus
Malicious code in qs-appbar-menus (npm)
28 Mar 2025
No fix available
MAL-2024-2909
npm/@ozon-shared-deps/qs
Malicious code in @ozon-shared-deps/qs (npm)
25 Jun 2024
No fix available
GHSA-hrpp-h998-j3pp
npm/qs
qs vulnerable to Prototype Pollution
27 Nov 2022
Fix available
Severity - 7.5 (High)
MAL-2022-5559
npm/qs-state-visualizer
Malicious code in qs-state-visualizer (npm)
20 Jun 2022
No fix available
GHSA-gqgv-6jq5-jjj9
npm/qs
Prototype Pollution Protection Bypass in qs
30 Apr 2020
Fix available
Severity - 7.5 (High)
GHSA-f9cm-p3w6-xvr3
npm/qs
Denial-of-Service Extended Event Loop Blocking in qs
09 Oct 2018
Fix available
GHSA-jjv7-qpx3-h62q
npm/qs
Denial-of-Service Memory Exhaustion in qs
24 Oct 2017
Fix available
npm - OSV