qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&a[__proto__]&a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has “deps: qs@6.9.7” in its release description, is not vulnerable).
More Stories
python-jinja2-3.1.5-1.fc40
FEDORA-2025-6ed1e0c3c6 Packages in this update: python-jinja2-3.1.5-1.fc40 Update description: Update to 3.1.5 Security fix for CVE-2024-56201 Read More
python-jinja2-3.1.5-1.fc41
FEDORA-2025-7b6e208ef2 Packages in this update: python-jinja2-3.1.5-1.fc41 Update description: Update to 3.1.5 Security fix for CVE-2024-56201 Read More
chromium-131.0.6778.264-1.el9
FEDORA-EPEL-2025-56fc9b1754 Packages in this update: chromium-131.0.6778.264-1.el9 Update description: Update to 131.0.6778.264 * High CVE-2025-0291: Type Confusion in V8 Read More
chromium-131.0.6778.264-1.fc41
FEDORA-2025-212c5c45ce Packages in this update: chromium-131.0.6778.264-1.fc41 Update description: Update to 131.0.6778.264 * High CVE-2025-0291: Type Confusion in V8 Read More
chromium-131.0.6778.264-1.el10_0
FEDORA-EPEL-2025-10c786286b Packages in this update: chromium-131.0.6778.264-1.el10_0 Update description: Update to 131.0.6778.264 * High CVE-2025-0291: Type Confusion in V8 Read More
chromium-131.0.6778.264-1.el8
FEDORA-EPEL-2025-b65cef2f93 Packages in this update: chromium-131.0.6778.264-1.el8 Update description: Update to 131.0.6778.264 * High CVE-2025-0291: Type Confusion in V8 Read More