CVE-2014-7191
Denial-of-Service Memory Exhaustion in qs
EPSS 0.69%
Description
The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.
How to fix CVE-2014-7191
To remediate CVE-2014-7191, upgrade the affected package to a fixed version below.
- Debian/node-qs—upgrade to 2.2.4-1 or later
- npm/qs—upgrade to 1.0.0 or later
Is CVE-2014-7191 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.2.4-1
- from 0, < 1.0.0