VYPR

Qs

by Ljharb

npm: qs

Source repositories

CVEs (4)

  • CVE-2026-82417MedAug 30, 2026
    risk 0.27cvss 5.3epss 0.00

    ### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is…

  • CVE-2026-8723MedMay 17, 2026
    risk 0.27cvss 5.3epss 0.00

    ### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`). …

  • CVE-2026-82562LowAug 30, 2026
    risk 0.17cvss 3.7epss 0.01

    ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the same value under a flat key (`a=1,2,3,4`),…

  • CVE-2025-15284LowDec 29, 2025
    risk 0.17cvss 3.7epss 0.00

    Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug;…