Search CVE reports


Toggle filters

1 – 5 of 5 results


CVE-2022-24999

Medium priority

Some fixes available 1 of 5

qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an...

2 affected packages

node-express, node-qs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-express Not affected Not affected Vulnerable Not affected
node-qs Not affected Not affected Fixed Not affected
Show less packages

CVE-2021-44907

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

1 affected package

node-qs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-qs Not affected Not affected Not affected
Show less packages

CVE-2017-1000048

Medium priority
Ignored

the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.

1 affected package

node-qs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-qs Not affected
Show less packages

CVE-2014-7191

Medium priority

Some fixes available 1 of 7

The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

1 affected package

node-qs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-qs Not affected Not affected Not affected
Show less packages

CVE-2014-10064

Medium priority
Vulnerable

The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of time. An attacker could leverage...

1 affected package

node-qs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-qs Not affected Not affected Not affected Not affected
Show less packages