CVE-2026-82562 (Low) detected in qs-6.15.1.tgz
还没有人认领这个 Issue。
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 75/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- cypress, javascript
- 领域
- security
调研方向
从 /ui/package.json 开始,沿着报告的依赖路径经过 cypress 和 request 跟踪到 qs。将解析后的 qs 版本升级到 6.16.0,然后验证依赖树中不再包含 qs 6.15.1。
由索引模型根据 Issue 内容生成。
描述
CVE-2026-82562 - Low Severity Vulnerability
Vulnerable Library - qs-6.15.1.tgz
A querystring parser that supports nesting and arrays, with a depth limit
Library home page: https://registry.npmjs.org/qs/-/qs-6.15.1.tgz
Sample Path to Dependency File: /ui/package.json
Path to vulnerable library: /ui/node_modules/.pnpm/[email protected]/node_modules/qs/package.json
Dependency Hierarchy:
- @postgres.ai/ce-4.0.3.tgz (Root Library)
- cypress-14.5.4.tgz
- request-3.0.10.tgz
- ❌ qs-6.15.1.tgz (Vulnerable Library)
- request-3.0.10.tgz
- cypress-14.5.4.tgz
Found in base branch: master
Vulnerability Details
Summary
When "qs.parse" is called with "comma: true" and "throwOnLimitExceeded: true", a comma-separated value under a bracket-push key ("a[]=1,2,3,4") is split into an array without being compared against "arrayLimit", while the same value under a flat key ("a=1,2,3,4"), an indexed key ("a[0]="), a nested key ("a[b]="), or a dotted key ("a.b=" with "allowDots") throws the documented "RangeError". A single parameter such as "a[]=1,2,2,..." therefore produces an inner array of arbitrary length even though the caller opted into the hard limit. This is the "[]=" key form that the fix for CVE-2026-2391 (qs 6.14.2) did not cover.
Details
In "lib/parse.js", a comma-separated value under a "[]=" key is split and then wrapped as a single nested element ("val = [val]", so that each "a[]=x,y" group counts as one element of the outer array). The "arrayLimit" check that 6.14.2 added for comma values runs after that wrap, so for "[]=" parts it only ever saw the wrapper of length 1. 6.15.3 added a pre-split comma count so that an oversized value throws before it is allocated, but gated it on an "isFlatArrayValue" flag that "parseValues" set to "false" for any part containing "[]=", and did not pass it for object-valued input, so the gap remained.
PoC
Fix
"lib/parse.js", applied in 8859c37 on "main" and released as v6.16.0: the "isFlatArrayValue" gate is removed, so every comma-split value is counted against "arrayLimit" before splitting regardless of key form. An in-limit group under "a[]=" still counts as one element of the outer array, and the default ("throwOnLimitExceeded: false") path is unchanged.
Affected versions
">=6.14.2 <6.16.0", fixed in v6.16.0.
v6.14.2 introduced "arrayLimit" enforcement for comma values (the fix for CVE-2026-2391) but only for values not under a "[]=" key, and every release from v6.14.2 through v6.15.3 has the same gap. v6.14.0 and v6.14.1, where "throwOnLimitExceeded" exists but does not apply to any comma form, are covered by CVE-2026-2391 rather than this record. Earlier lines (6.7.x through 6.13.x) have "comma" but no "throwOnLimitExceeded", so there is no hard cap on any comma path to bypass; releases before 6.7.0 have no "comma" option.
Impact
An unauthenticated attacker who can reach an application that parses untrusted query strings or urlencoded bodies with both "comma: true" and "throwOnLimitExceeded: true" (both non-default) can bypass the configured limit with a single "a[]=" parameter and force the parser to allocate an array proportional to the request size. The cost is strictly linear in the attacker-supplied bytes (about 0.1 microseconds and 6 to 7 retained bytes per input byte; the same out-of-memory threshold as the documented default "throwOnLimitExceeded: false" path), so a transport-layer request or body size limit bounds it completely (and node's default maximum HTTP header size of 16 KB already bounds the request line, so multi-megabyte payloads need a body parser). The impact is that an opt-in hard limit fails open on one key spelling, not unbounded allocation from a small input.
Mend Note: The description of this vulnerability differs from MITRE.
Publish Date: 2026-08-29
URL: CVE-2026-82562
CVSS 3 Score Details (3.7)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
Suggested Fix
Type: Upgrade version
Origin: https://github.com/ljharb/qs/security/advisories/GHSA-w7fw-mjwx-w883
Release Date: 2026-08-29
Fix Resolution: qs - 6.16.0,qs - 6.16.0,https://github.com/ljharb/qs.git - v6.16.0
Step up your Open Source Security Game with Mend here
- 主要语言
- Go
- 星标
- 2.7k
- 派生
- 85
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
postgres-ai/database-lab-engine 的其他 Issue
-
Mend: dependency security vulnerability
难度 2/5 1-3 小时 新手友好度 75/100
-
Mend: dependency security vulnerability
难度 2/5 1-3 小时 新手友好度 75/100
-
Mend: dependency security vulnerability
难度 1/5 1 小时以内 新手友好度 86/100
-
Mend: dependency security vulnerability
难度 2/5 1-3 小时 新手友好度 84/100
-
Mend: dependency security vulnerability
难度 2/5 1-3 小时 新手友好度 85/100
查看 postgres-ai/database-lab-engine 的全部 Issue
相似的 Issue
-
agent-butler-finding chore
难度 1/5 1 小时以内 新手友好度 88/100
jordansmall/spindrift#4146 ·
维护者通常 1 天内回复
-
security
难度 2/5 1-3 小时 新手友好度 68/100
IBM/ibmcloud-volume-file-vpc#119 ·
-
security
难度 2/5 1-3 小时 新手友好度 66/100
IBM/networking-go-sdk#339 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
kubernetes-sigs/mcp-lifecycle-operator#439 ·
维护者通常 1 天内回复
-
area: global bug dx priority: low
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复