The Qs Project maintains a focused query-string parsing library whose compactness belies its presence across downstream web applications and frameworks that depend on string-handling utilities. Observed vulnerabilities center on input-validation gaps and prototype-pollution conditions, exposures typical of lightweight parsing and object-manipulation libraries where boundary enforcement and property-access control are critical to safety.
The number and severity of CVEs published that impact products developed by Qs Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24999HIGH qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be use | Nov 26, 2022 | 7.5 | 32 | NO | NO |
CVE-2026-2391HIGH ### Summary
The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory | Feb 12, 2026 | 7.5 | 27 | NO | NO |
CVE-2017-1000048HIGH the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework | Jul 17, 2017 | 7.5 | 23 | NO | NO |
Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1.
Summary
The arrayLimit option in qs did not enforce limits for bra | Dec 29, 2025 | 3.7 | 21 | NO | NO |
CVE-2014-10064HIGH The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop fo | May 31, 2018 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qs Project.
Media articles that mention a CVE ID that affects a product developed by Qs Project — matched by CVE ID, not by vendor name.