Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

CVE-2026-82562 (Low) detected in qs-6.15.1.tgz

未关闭 适合新手
#388 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
2/5
预计耗时
1-3 小时
新手友好度
75/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
cypress, javascript
领域
security

调研方向

从 /ui/package.json 开始,沿着报告的依赖路径经过 cypress 和 request 跟踪到 qs。将解析后的 qs 版本升级到 6.16.0,然后验证依赖树中不再包含 qs 6.15.1。

由索引模型根据 Issue 内容生成。

描述

Mend: dependency security vulnerability

CVE-2026-82562 - Low Severity Vulnerability

Vulnerable Library - qs-6.15.1.tgz

A querystring parser that supports nesting and arrays, with a depth limit

Library home page: https://registry.npmjs.org/qs/-/qs-6.15.1.tgz

Sample Path to Dependency File: /ui/package.json

Path to vulnerable library: /ui/node_modules/.pnpm/[email protected]/node_modules/qs/package.json

Dependency Hierarchy:

  • @⁠postgres.ai/ce-4.0.3.tgz (Root Library)
    • cypress-14.5.4.tgz
      • request-3.0.10.tgz
        • ❌ qs-6.15.1.tgz (Vulnerable Library)

Found in base branch: master

Vulnerability Details

Summary
When "qs.parse" is called with "comma: true" and "throwOnLimitExceeded: true", a comma-separated value under a bracket-push key ("a[]=1,2,3,4") is split into an array without being compared against "arrayLimit", while the same value under a flat key ("a=1,2,3,4"), an indexed key ("a[0]="), a nested key ("a[b]="), or a dotted key ("a.b=" with "allowDots") throws the documented "RangeError". A single parameter such as "a[]=1,2,2,..." therefore produces an inner array of arbitrary length even though the caller opted into the hard limit. This is the "[]=" key form that the fix for CVE-2026-2391 (qs 6.14.2) did not cover.
Details
In "lib/parse.js", a comma-separated value under a "[]=" key is split and then wrapped as a single nested element ("val = [val]", so that each "a[]=x,y" group counts as one element of the outer array). The "arrayLimit" check that 6.14.2 added for comma values runs after that wrap, so for "[]=" parts it only ever saw the wrapper of length 1. 6.15.3 added a pre-split comma count so that an oversized value throws before it is allocated, but gated it on an "isFlatArrayValue" flag that "parseValues" set to "false" for any part containing "[]=", and did not pass it for object-valued input, so the gap remained.
PoC
Fix
"lib/parse.js", applied in 8859c37 on "main" and released as v6.16.0: the "isFlatArrayValue" gate is removed, so every comma-split value is counted against "arrayLimit" before splitting regardless of key form. An in-limit group under "a[]=" still counts as one element of the outer array, and the default ("throwOnLimitExceeded: false") path is unchanged.
Affected versions
">=6.14.2 <6.16.0", fixed in v6.16.0.
v6.14.2 introduced "arrayLimit" enforcement for comma values (the fix for CVE-2026-2391) but only for values not under a "[]=" key, and every release from v6.14.2 through v6.15.3 has the same gap. v6.14.0 and v6.14.1, where "throwOnLimitExceeded" exists but does not apply to any comma form, are covered by CVE-2026-2391 rather than this record. Earlier lines (6.7.x through 6.13.x) have "comma" but no "throwOnLimitExceeded", so there is no hard cap on any comma path to bypass; releases before 6.7.0 have no "comma" option.
Impact
An unauthenticated attacker who can reach an application that parses untrusted query strings or urlencoded bodies with both "comma: true" and "throwOnLimitExceeded: true" (both non-default) can bypass the configured limit with a single "a[]=" parameter and force the parser to allocate an array proportional to the request size. The cost is strictly linear in the attacker-supplied bytes (about 0.1 microseconds and 6 to 7 retained bytes per input byte; the same out-of-memory threshold as the documented default "throwOnLimitExceeded: false" path), so a transport-layer request or body size limit bounds it completely (and node's default maximum HTTP header size of 16 KB already bounds the request line, so multi-megabyte payloads need a body parser). The impact is that an opt-in hard limit fails open on one key spelling, not unbounded allocation from a small input.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2026-08-29

URL: CVE-2026-82562

CVSS 3 Score Details (3.7)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/ljharb/qs/security/advisories/GHSA-w7fw-mjwx-w883

Release Date: 2026-08-29

Fix Resolution: qs - 6.16.0,qs - 6.16.0,https://github.com/ljharb/qs.git - v6.16.0


Step up your Open Source Security Game with Mend here

主要语言
Go
星标
2.7k
派生
85
PR 合并指标
30 天内没有已合并 PR

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

postgres-ai/database-lab-engine 的其他 Issue

查看 postgres-ai/database-lab-engine 的全部 Issue

相似的 Issue

更多 Go Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。