Executive brief
The qs module is a popular Node.js query string parser used by web applications to process URL parameters. A flaw in how it handles array data allows an attacker to create sparse arrays with large index values, consuming excessive memory and causing the application to become unresponsive or crash (denial of service).
Technical details
The qs module before version 1.0.0 fails to call the compact function when processing array data during query string parsing. An attacker can exploit this by sending a request with specially crafted query parameters that include large array index values, which creates sparse arrays that consume significant memory. The vulnerability is remotely exploitable via network access to any application using the affected qs version and does not require authentication. This results in denial of service through memory exhaustion. The vulnerability was patched in qs 1.0.0.
Affected products
- npm qs before 1.0.0
Timeline
- 2018-10-09: disclosed: Published to GitHub Advisory Database
- 1.0.0: patched: Vulnerability patched in qs 1.0.0
- 2020-06-16: other: Advisory withdrawn as accidental duplicate