Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-x5fp-wj9c-mxmx
  • npm/qs
qs array-limit bypass via bracket-key comma parsing 02 Sep
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-4mjr-xmp4-gh2g
  • npm/qs
qs: Denial of Service via Attacker Controlled isBuffer 02 Sep
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-q8mj-m7cp-5q26
  • npm/qs
qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set 22 May
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-w7fw-mjwx-w883
  • npm/qs
qs's arrayLimit bypass in comma parsing allows denial of service 12 Feb
  • Fix available
  • Severity - 3.7 (Low)
MAL-2026-528
  • npm/@shije/new-qs
Malicious code in @shije/new-qs (npm) 27 Jan
  • No fix available
GHSA-6rw7-vpxm-498p
  • npm/qs
qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion 30 Dec 2025
  • Fix available
  • Severity - 6.3 (Medium)
MAL-2025-13485
  • npm/@zalastax/nolb-qs
Malicious code in @zalastax/nolb-qs (npm) 14 Aug 2025
  • No fix available
MAL-2025-31049
  • npm/qs-test-pro
Malicious code in qs-test-pro (npm) 14 Aug 2025
  • No fix available
MAL-2025-2892
  • npm/qs-appbar-menus
Malicious code in qs-appbar-menus (npm) 28 Mar 2025
  • No fix available
MAL-2024-2909
  • npm/@ozon-shared-deps/qs
Malicious code in @ozon-shared-deps/qs (npm) 25 Jun 2024
  • No fix available
GHSA-hrpp-h998-j3pp
  • npm/qs
qs vulnerable to Prototype Pollution 27 Nov 2022
  • Fix available
  • Severity - 7.5 (High)
MAL-2022-5559
  • npm/qs-state-visualizer
Malicious code in qs-state-visualizer (npm) 20 Jun 2022
  • No fix available
GHSA-gqgv-6jq5-jjj9
  • npm/qs
Prototype Pollution Protection Bypass in qs 30 Apr 2020
  • Fix available
  • Severity - 7.5 (High)
GHSA-f9cm-p3w6-xvr3
  • npm/qs
Denial-of-Service Extended Event Loop Blocking in qs 09 Oct 2018
  • Fix available
GHSA-jjv7-qpx3-h62q
  • npm/qs
Denial-of-Service Memory Exhaustion in qs 24 Oct 2017
  • Fix available