| Bug | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-82562 | vulnerable | vulnerable (no DSA) | fixed | fixed | ### Summary When `qs.parse` is called with `comma: true` and `throw ... |
| CVE-2026-82417 | vulnerable | vulnerable (no DSA) | fixed | fixed | ### Summary `qs.stringify` throws a `TypeError` when it serializes ... |
| CVE-2026-8723 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | ### Summary `qs.stringify` throws `TypeError` when called with `arr ... |
| CVE-2026-2391 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | ### Summary The `arrayLimit` option in qs does not enforce limits for ... |
| CVE-2025-15284 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Improper Input Validation vulnerability in qs (parse modules) allows H ... |