chore(deps): update dependency qs to v6.7.3 [security] - #96
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
October 15, 2023 17:05
193c20d to
2f319d2
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
October 23, 2023 17:57
2f319d2 to
7190cc8
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
January 15, 2024 10:05
7190cc8 to
a58bf91
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
February 4, 2024 09:34
a58bf91 to
eac8eff
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
February 25, 2024 11:18
eac8eff to
4df3610
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
March 12, 2024 12:44
4df3610 to
3e9393f
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
April 14, 2024 08:34
3e9393f to
a4cc519
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
July 21, 2024 14:32
a4cc519 to
0ce4633
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
August 6, 2024 06:50
0ce4633 to
933b40b
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
December 2, 2024 10:24
933b40b to
45b365c
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
January 23, 2025 21:12
45b365c to
3276ef6
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
February 9, 2025 14:13
3276ef6 to
3d87d52
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
March 3, 2025 12:20
3d87d52 to
23f74db
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
March 11, 2025 11:43
23f74db to
31c8ac4
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
December 31, 2025 17:47
31c8ac4 to
13be348
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
2 times, most recently
from
February 17, 2026 16:05
dd75a89 to
30e28a0
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
April 8, 2026 18:08
30e28a0 to
23ff122
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
April 27, 2026 23:30
23ff122 to
52ca78f
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
May 18, 2026 10:39
52ca78f to
c73f1dd
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
May 28, 2026 21:15
c73f1dd to
18cf5aa
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
June 11, 2026 17:58
18cf5aa to
de7eeab
Compare
renovate
Bot
force-pushed
the
renovate/npm-qs-vulnerability
branch
from
July 12, 2026 17:12
de7eeab to
05978cb
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.7.0→6.7.3qs vulnerable to Prototype Pollution
CVE-2022-24999 / GHSA-hrpp-h998-j3pp
More information
Details
qs before 6.10.3 allows attackers to cause a Node process hang because an
__ proto__key can be used. In many typical web framework use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such asa[__proto__]=b&a[__proto__]&a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
ljharb/qs (qs)
v6.7.3Compare Source
parse: ignore__proto__keys (#428)stringify: avoid encoding arrayformat comma whenencodeValuesOnly = true(#424)stringify: avoid relying on a globalundefined(#427)nycfor coveragev6.7.2Compare Source
v6.7.1Compare Source
parse: Fix parsing array from object withcommatrue (#359)parse: with comma true, handle field that holds an array of arrays (#335)parse: with comma true, do not split non-string values (#334)parse: throw a TypeError instead of an Error for bad charset (#349)formats: tiny bit of cleanup.fundingfieldeslint,@ljharb/eslint-config,tape,safe-publish-latest,evalmd,iconv-lite,mkdirp,object-inspect,browserifyparse: add passingarrayFormattestsBuffer.fromin node v5.0-v5.9 and v4.0-v4.4 requires a TypedArraydepth=0anddepth=falsebehavior, both current and intuitive/intendedeclintinstead ofeditorconfig-toolsConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.