CVE-2026-82562 - Low Severity Vulnerability
Vulnerable Library - qs-6.15.1.tgz
A querystring parser that supports nesting and arrays, with a depth limit
Library home page: https://registry.npmjs.org/qs/-/qs-6.15.1.tgz
Sample Path to Dependency File: /ui/package.json
Path to vulnerable library: /ui/node_modules/.pnpm/qs@6.15.1/node_modules/qs/package.json
Dependency Hierarchy:
- @postgres.ai/ce-4.0.3.tgz (Root Library)
- cypress-14.5.4.tgz
- request-3.0.10.tgz
- ❌ qs-6.15.1.tgz (Vulnerable Library)
Found in base branch: master
Vulnerability Details
Summary
When "qs.parse" is called with "comma: true" and "throwOnLimitExceeded: true", a comma-separated value under a bracket-push key ("a[]=1,2,3,4") is split into an array without being compared against "arrayLimit", while the same value under a flat key ("a=1,2,3,4"), an indexed key ("a[0]="), a nested key ("a[b]="), or a dotted key ("a.b=" with "allowDots") throws the documented "RangeError". A single parameter such as "a[]=1,2,2,..." therefore produces an inner array of arbitrary length even though the caller opted into the hard limit. This is the "[]=" key form that the fix for CVE-2026-2391 (qs 6.14.2) did not cover.
Details
In "lib/parse.js", a comma-separated value under a "[]=" key is split and then wrapped as a single nested element ("val = [val]", so that each "a[]=x,y" group counts as one element of the outer array). The "arrayLimit" check that 6.14.2 added for comma values runs after that wrap, so for "[]=" parts it only ever saw the wrapper of length 1. 6.15.3 added a pre-split comma count so that an oversized value throws before it is allocated, but gated it on an "isFlatArrayValue" flag that "parseValues" set to "false" for any part containing "[]=", and did not pass it for object-valued input, so the gap remained.
PoC
Fix
"lib/parse.js", applied in 8859c37 on "main" and released as v6.16.0: the "isFlatArrayValue" gate is removed, so every comma-split value is counted against "arrayLimit" before splitting regardless of key form. An in-limit group under "a[]=" still counts as one element of the outer array, and the default ("throwOnLimitExceeded: false") path is unchanged.
Affected versions
">=6.14.2 <6.16.0", fixed in v6.16.0.
v6.14.2 introduced "arrayLimit" enforcement for comma values (the fix for CVE-2026-2391) but only for values not under a "[]=" key, and every release from v6.14.2 through v6.15.3 has the same gap. v6.14.0 and v6.14.1, where "throwOnLimitExceeded" exists but does not apply to any comma form, are covered by CVE-2026-2391 rather than this record. Earlier lines (6.7.x through 6.13.x) have "comma" but no "throwOnLimitExceeded", so there is no hard cap on any comma path to bypass; releases before 6.7.0 have no "comma" option.
Impact
An unauthenticated attacker who can reach an application that parses untrusted query strings or urlencoded bodies with both "comma: true" and "throwOnLimitExceeded: true" (both non-default) can bypass the configured limit with a single "a[]=" parameter and force the parser to allocate an array proportional to the request size. The cost is strictly linear in the attacker-supplied bytes (about 0.1 microseconds and 6 to 7 retained bytes per input byte; the same out-of-memory threshold as the documented default "throwOnLimitExceeded: false" path), so a transport-layer request or body size limit bounds it completely (and node's default maximum HTTP header size of 16 KB already bounds the request line, so multi-megabyte payloads need a body parser). The impact is that an opt-in hard limit fails open on one key spelling, not unbounded allocation from a small input.
Mend Note: The description of this vulnerability differs from MITRE.
Publish Date: 2026-08-29
URL: CVE-2026-82562
CVSS 3 Score Details (3.7)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-w7fw-mjwx-w883
Release Date: 2026-08-29
Fix Resolution: qs - 6.16.0,qs - 6.16.0,https://github.com/ljharb/qs.git - v6.16.0
Step up your Open Source Security Game with Mend here
CVE-2026-82562 - Low Severity Vulnerability
A querystring parser that supports nesting and arrays, with a depth limit
Library home page: https://registry.npmjs.org/qs/-/qs-6.15.1.tgz
Sample Path to Dependency File: /ui/package.json
Path to vulnerable library: /ui/node_modules/.pnpm/qs@6.15.1/node_modules/qs/package.json
Dependency Hierarchy:
Found in base branch: master
Summary
When "qs.parse" is called with "comma: true" and "throwOnLimitExceeded: true", a comma-separated value under a bracket-push key ("a[]=1,2,3,4") is split into an array without being compared against "arrayLimit", while the same value under a flat key ("a=1,2,3,4"), an indexed key ("a[0]="), a nested key ("a[b]="), or a dotted key ("a.b=" with "allowDots") throws the documented "RangeError". A single parameter such as "a[]=1,2,2,..." therefore produces an inner array of arbitrary length even though the caller opted into the hard limit. This is the "[]=" key form that the fix for CVE-2026-2391 (qs 6.14.2) did not cover.
Details
In "lib/parse.js", a comma-separated value under a "[]=" key is split and then wrapped as a single nested element ("val = [val]", so that each "a[]=x,y" group counts as one element of the outer array). The "arrayLimit" check that 6.14.2 added for comma values runs after that wrap, so for "[]=" parts it only ever saw the wrapper of length 1. 6.15.3 added a pre-split comma count so that an oversized value throws before it is allocated, but gated it on an "isFlatArrayValue" flag that "parseValues" set to "false" for any part containing "[]=", and did not pass it for object-valued input, so the gap remained.
PoC
Fix
"lib/parse.js", applied in 8859c37 on "main" and released as v6.16.0: the "isFlatArrayValue" gate is removed, so every comma-split value is counted against "arrayLimit" before splitting regardless of key form. An in-limit group under "a[]=" still counts as one element of the outer array, and the default ("throwOnLimitExceeded: false") path is unchanged.
Affected versions
">=6.14.2 <6.16.0", fixed in v6.16.0.
v6.14.2 introduced "arrayLimit" enforcement for comma values (the fix for CVE-2026-2391) but only for values not under a "[]=" key, and every release from v6.14.2 through v6.15.3 has the same gap. v6.14.0 and v6.14.1, where "throwOnLimitExceeded" exists but does not apply to any comma form, are covered by CVE-2026-2391 rather than this record. Earlier lines (6.7.x through 6.13.x) have "comma" but no "throwOnLimitExceeded", so there is no hard cap on any comma path to bypass; releases before 6.7.0 have no "comma" option.
Impact
An unauthenticated attacker who can reach an application that parses untrusted query strings or urlencoded bodies with both "comma: true" and "throwOnLimitExceeded: true" (both non-default) can bypass the configured limit with a single "a[]=" parameter and force the parser to allocate an array proportional to the request size. The cost is strictly linear in the attacker-supplied bytes (about 0.1 microseconds and 6 to 7 retained bytes per input byte; the same out-of-memory threshold as the documented default "throwOnLimitExceeded: false" path), so a transport-layer request or body size limit bounds it completely (and node's default maximum HTTP header size of 16 KB already bounds the request line, so multi-megabyte payloads need a body parser). The impact is that an opt-in hard limit fails open on one key spelling, not unbounded allocation from a small input.
Mend Note: The description of this vulnerability differs from MITRE.
Publish Date: 2026-08-29
URL: CVE-2026-82562
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Type: Upgrade version
Origin: GHSA-w7fw-mjwx-w883
Release Date: 2026-08-29
Fix Resolution: qs - 6.16.0,qs - 6.16.0,https://github.com/ljharb/qs.git - v6.16.0
Step up your Open Source Security Game with Mend here