SCA: security update for qs (GHSA-6rw7-vpxm-498p)

medium Tenable Cloud Security Plugin ID 436528

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: <
6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2),
only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit should apply uniformly across
all array notations. Note: The default parameterLimit of 1000 effectively mitigates the DoS scenario
originally described. With default options, bracket notation cannot produce arrays larger than
parameterLimit regardless of arrayLimit, because each a[]=valueconsumes one parameter slot. The severity
has been reduced accordingly. Details The arrayLimit option only checked limits for indexed notation
(a[0]=1&a[1]=2) but did not enforce it for bracket notation (a[]=1&a[]=2). Vulnerable code
(lib/parse.js:159-162): if (root === '[]' && options.parseArrays) { obj = utils.combine([], leaf); // No
arrayLimit check } Working code (lib/parse.js:175): else if (index <= options.arrayLimit) { // Limit
checked here obj = []; obj[index] = leaf; } The bracket notation handler at line 159 uses
utils.combine([], leaf) without validating against options.arrayLimit, while indexed notation at line 175
checks index <= options.arrayLimit before creating arrays. PoC const qs = require('qs'); const result =
qs.parse('a[]=1&a[]=2&a[]=3&a[]=4&a[]=5&a[]=6', { arrayLimit: 5 }); console.log(result.a.length); //
Output: 6 (should be max 5) Note on parameterLimit interaction: The original advisory's "DoS
demonstration" claimed a length of 10,000, but parameterLimit (default: 1000) caps parsing to 1,000
parameters. With default options, the actual output is 1,000, not 10,000. Impact Consistency bug in
arrayLimit enforcement. With default parameterLimit, the practical DoS risk is negligible since
parameterLimit already caps the total number of parsed parameters (and thus array elements from bracket
notation). The risk increases only when parameterLimit is explicitly set to a very high value.
(CVE-2025-15284)

See Also

https://github.com/advisories/GHSA-6rw7-vpxm-498p

Plugin Details

Severity: Medium

ID: 436528

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 12/31/2025

Updated: 7/20/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.82

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 2

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2025-15284

CVSS v3

Risk Factor: Low

Base Score: 3.7

Temporal Score: 3.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.3

Threat Score: 2.9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/30/2025

Vulnerability Publication Date: 12/29/2025

Reference Information

CVE: CVE-2025-15284

cwe: CWE-20