the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| qs(npm) | 0 | 6.0.4 | N/A |
| qs(npm) | 6.1.0 | 6.1.2 | N/A |
| qs(npm) | 6.2.0 | 6.2.3 | N/A |
| qs(npm) | 6.3.0 | 6.3.2 | N/A |
CVSS Metrics