| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-8723 | vulnerable (no DSA, postponed) | vulnerable | vulnerable | vulnerable | vulnerable | ### Summary `qs.stringify` throws `TypeError` when called with `arr ... |
| CVE-2026-2391 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | ### Summary The `arrayLimit` option in qs does not enforce limits for ... |
| CVE-2025-15284 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Improper Input Validation vulnerability in qs (parse modules) allows H ... |