Denial-of-Service Extended Event Loop Blocking in qs
High severity
GitHub Reviewed
Published
Oct 9, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Oct 9, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Versions prior to 1.0.0 of
qs
are affected by a denial of service vulnerability that results from excessive recursion in parsing a deeply nested JSON string.Recommendation
Update to version 1.0.0 or later
References