{"id":"CVE-2014-7191","aliases":["GHSA-jjv7-qpx3-h62q"],"url":"https://o3.security/vulnerability/CVE-2014-7191","summary":"Denial-of-Service Memory Exhaustion in qs","details":"Versions prior to 1.0 of `qs` are affected by a denial of service condition. This condition is triggered by parsing a crafted string that deserializes into very large sparse arrays, resulting in the process running out of memory and eventually crashing.\n\n\n## Recommendation\n\nUpdate to version 1.0.0 or later.","published":"2014-10-19T01:55:21Z","modified":"2026-04-10T03:44:01.105238Z","cvss":null,"epss":{"score":0.08309,"percentile":0.94557,"asOf":"2026-09-06"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"qs","fixedVersion":"1.0.0"}],"fix":{"url":"https://github.com/raymondfeng/node-querystring/commit/43a604b7847e56bba49d0ce3e222fe89569354d8","label":"raymondfeng/node-querystring@43a604b"},"references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/60026"},{"type":"ADVISORY","url":"http://secunia.com/advisories/62170"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2016:1380"},{"type":"ADVISORY","url":"https://nodesecurity.io/advisories/qs_dos_memory_exhaustion"},{"type":"FIX","url":"https://github.com/raymondfeng/node-querystring/commit/43a604b7847e56bba49d0ce3e222fe89569354d8"},{"type":"REPORT","url":"https://github.com/visionmedia/node-querystring/issues/104"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21685987"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21687263"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21687928"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/96729"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-7191"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jjv7-qpx3-h62q"},{"type":"PACKAGE","url":"https://github.com/visionmedia/node-querystring"},{"type":"WEB","url":"https://www.npmjs.com/advisories/29"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:44:01.105238Z"}}