Array Parsing Vulnerability in qs Library by Node.js Developer
CVE-2026-82562
6.3MEDIUM
What is CVE-2026-82562?
A vulnerability exists in the 'qs' library when using the 'comma' option set to true along with 'throwOnLimitExceeded' enabled. An attacker can exploit this flaw to bypass configured array limits by passing an oversized comma-separated value under a bracketed key (e.g., 'a[]=1,2,3,4'). Despite the limit set, the parser allows for unbounded allocations, as the array limit check only assesses non-bracketed keys. This vulnerability could lead to denial of service by exhausting server resources, and it impacts all versions from 6.14.2 to 6.15.3, which failed to adequately enforce limits on such array inputs. The issue was patched in version 6.16.0.
Affected Version(s)
qs 6.14.2 < 6.16.0
