CVE-2026-32701 impacts Qwik framework versions prior to 1.19.2, where improper array inference during FormData parsing allows attackers to manipulate dotted form field names. This enables user-controlled properties to be written onto values expected to be arrays, leading to type confusion and potential denial of service. With a CVSS score of 7.5 (High), this vulnerability has a network attack vector, low complexity, requires no privileges or user interaction, and primarily impacts availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion for this issue. The vulnerability was addressed in Qwik version 1.19.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.19.2CPE matchmatch criteria | cpe:2.3:a:qwik:qwik:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.