the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.
2017-07-17T13:18:17.453
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | qs_project | qs | 1.0.0 | Yes |
Application | qs_project | qs | 1.0.1 | Yes |
Application | qs_project | qs | 1.0.2 | Yes |
Application | qs_project | qs | 1.1.0 | Yes |
Application | qs_project | qs | 1.2.0 | Yes |
Application | qs_project | qs | 1.2.1 | Yes |
Application | qs_project | qs | 2.3.1 | Yes |
Application | qs_project | qs | 2.3.2 | Yes |
Application | qs_project | qs | 2.3.3 | Yes |
Application | qs_project | qs | 2.4.0 | Yes |
Application | qs_project | qs | 2.4.1 | Yes |
Application | qs_project | qs | 2.4.2 | Yes |
Application | qs_project | qs | 3.0.0 | Yes |
Application | qs_project | qs | 3.1.0 | Yes |
Application | qs_project | qs | 4.0.0 | Yes |
Application | qs_project | qs | 5.0.0 | Yes |
Application | qs_project | qs | 5.1.0 | Yes |
Application | qs_project | qs | 5.2.0 | Yes |
Application | qs_project | qs | 5.2.1 | Yes |
Application | qs_project | qs | 6.0.0 | Yes |
Application | qs_project | qs | 6.0.1 | Yes |
Application | qs_project | qs | 6.0.2 | Yes |
Application | qs_project | qs | 6.0.3 | Yes |
Application | qs_project | qs | 6.1.0 | Yes |
Application | qs_project | qs | 6.1.1 | Yes |
Application | qs_project | qs | 6.2.0 | Yes |
Application | qs_project | qs | 6.2.1 | Yes |
Application | qs_project | qs | 6.2.2 | Yes |
Application | qs_project | qs | 6.3.0 | Yes |
Application | qs_project | qs | 6.3.1 | Yes |