{"id":"CVE-2014-10064","aliases":["GHSA-f9cm-p3w6-xvr3"],"url":"https://o3.security/vulnerability/CVE-2014-10064","summary":"Denial-of-Service Extended Event Loop Blocking in qs","details":"The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of time. An attacker could leverage this to cause a temporary denial-of-service condition, for example, in a web application, other requests would not be processed while this blocking is occurring.","published":"2018-05-31T20:29:00Z","modified":"2026-04-10T03:43:34.504498Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"qs","fixedVersion":"1.0.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nodesecurity.io/advisories/28"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:43:34.504498Z"}}