A querystring parser that supports nesting and arrays, with a depth limit
86%
Total Score
78
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-8723 New qs is vulnerable to NULL Pointer Dereference in versions 6.11.1 - 6.15.1. | 6.11.1 - 6.15.1 | Medium |
CVE-2026-2391 qs is vulnerable to Improper Input Validation in versions 6.7.0 - 6.14.1. | 6.7.0 - 6.14.1 | Low |
CVE-2025-15284 qs is vulnerable to Improper Input Validation in versions 0.0.0 - 6.14.1. | 0.0.0 - 6.14.1 | Low |
CVE-2022-24999 qs is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 6.10.0 - 6.10.3, 6.9.0 - 6.9.7, 6.8.0 - 6.8.3, 6.7.0 - 6.7.3, 6.6.0 - 6.6.1, 6.5.0 - 6.5.3, 6.4.0 - 6.4.1, 6.3.0 - 6.3.3 and 0.0.0 - 6.2.4. | 0.0.0 - 6.2.46.3.0 - 6.3.36.4.0 - 6.4.1 +6 more | High |
CVE-2017-1000048 qs is vulnerable to Improper Input Validation in versions 0.0.0 - 6.0.4, 6.1.0 - 6.1.2, 6.2.0 - 6.2.3 and 6.3.0 - 6.3.2. | 0.0.0 - 6.0.46.1.0 - 6.1.26.2.0 - 6.2.3 +1 more | High |
| Dependency | Last Release | Score |
|---|---|---|
side-channel Version ^1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant