Junglewise Threat Intelligence

qs denial of service via sparse array

Severity: info · Published 2018-10-09

Vendors: npm.

Executive brief

The qs module is a popular Node.js query string parser used by web applications to process URL parameters. A flaw in how it handles array data allows an attacker to create sparse arrays with large index values, consuming excessive memory and causing the application to become unresponsive or crash (denial of service).

Technical details

The qs module before version 1.0.0 fails to call the compact function when processing array data during query string parsing. An attacker can exploit this by sending a request with specially crafted query parameters that include large array index values, which creates sparse arrays that consume significant memory. The vulnerability is remotely exploitable via network access to any application using the affected qs version and does not require authentication. This results in denial of service through memory exhaustion. The vulnerability was patched in qs 1.0.0.

Affected products

  • npm qs before 1.0.0

Timeline

  • 2018-10-09: disclosed: Published to GitHub Advisory Database
  • 1.0.0: patched: Vulnerability patched in qs 1.0.0
  • 2020-06-16: other: Advisory withdrawn as accidental duplicate