Vendorsqs Projectqsany version
Vulnerabilities

qs Project QS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-24999
qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&a[__proto__]&a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has "deps: qs@6.9.7" in its release description, is not vulnerable).
Published 2022-11-26 · Modified
7.5EPSS 0.151
CVE-2014-10064
The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of time. An attacker could leverage this to cause a temporary denial-of-service condition, for example, in a web application, other requests would not be processed while this blocking is occurring.
Published 2018-05-31 · Modified
7.5EPSS 0.013
CVE-2026-2391
qs's arrayLimit bypass in comma parsing allows denial of service
Published 2026-02-12 · Analyzed
7.5EPSS 0.005
CVE-2025-15284
arrayLimit bypass in bracket notation allows DoS via memory exhaustion
Published 2025-12-29 · Analyzed
6.3EPSS 0.005