{"id":"CVE-2017-1000048","aliases":["GHSA-gqgv-6jq5-jjj9"],"url":"https://o3.security/vulnerability/CVE-2017-1000048","summary":"Prototype Pollution Protection Bypass in qs","details":"the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.","published":"2017-07-17T13:18:17.453Z","modified":"2026-08-07T14:48:36.983645Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"qs","fixedVersion":"6.0.4"},{"ecosystem":"npm","name":"qs","fixedVersion":"6.1.2"},{"ecosystem":"npm","name":"qs","fixedVersion":"6.2.3"},{"ecosystem":"npm","name":"qs","fixedVersion":"6.3.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:2672"},{"type":"ADVISORY","url":"https://github.com/ljharb/qs/issues/200"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:48:36.983645Z"}}