Information on source package node-qs

Available versions

ReleaseVersion
bookworm6.11.0+ds+~6.9.7-3
trixie6.13.0+ds+~6.9.16-1
forky6.16.0+ds+~6.15.1-1
sid6.16.0+ds+~6.15.1-1

Open issues

BugbookwormtrixieforkysidDescription
CVE-2026-82562vulnerablevulnerable (no DSA)fixedfixed### Summary When `qs.parse` is called with `comma: true` and `throw ...
CVE-2026-82417vulnerablevulnerable (no DSA)fixedfixed### Summary `qs.stringify` throws a `TypeError` when it serializes ...
CVE-2026-8723vulnerable (no DSA)vulnerable (no DSA)fixedfixed### Summary `qs.stringify` throws `TypeError` when called with `arr ...
CVE-2026-2391vulnerable (no DSA)vulnerable (no DSA)fixedfixed### Summary The `arrayLimit` option in qs does not enforce limits for ...
CVE-2025-15284vulnerable (no DSA)vulnerable (no DSA)fixedfixedImproper Input Validation vulnerability in qs (parse modules) allows H ...

Resolved issues

BugDescription
CVE-2022-24999qs before 6.10.3, as used in Express before 4.17.3 and other products, ...
CVE-2014-10064The qs module before 1.0.0 does not have an option or default for spec ...
CVE-2014-7191The qs module before 1.0.0 in Node.js does not call the compact functi ...

Security announcements

DSA / DLADescription
DLA-3299-1node-qs - security update

Search for package or bug name: Reporting problems