CVE-2026-82417

Aliases:DEBIAN-CVE-2026-82417UBUNTU-CVE-2026-82417GHSA-4mjr-xmp4-gh2gCGA-24cr-fcrp-5c6rCGA-27q4-4hw4-pwhpCGA-36r6-4hwh-8828CGA-375m-2gch-8jvwCGA-3c5m-98mm-vrh2CGA-3f58-rc5w-6v83CGA-46w4-fp7x-p6h9CGA-4h84-j855-588cCGA-4rm9-pfv7-gg8cCGA-5q74-mhw4-x7w8CGA-6w5j-jgrq-f8q4CGA-7v8x-rw3c-h2h6CGA-7w6q-4j3m-77vjCGA-9c3p-hw2x-c99mCGA-9fmj-xvcp-7xrfCGA-9gph-5qpc-69p9CGA-9jj4-g2xq-5238CGA-9r9c-639g-69jhCGA-c3v3-frqj-q9cxCGA-c9cj-xmm7-2g5jCGA-f3q5-m3qq-6p5pCGA-f935-p5pg-7ghrCGA-fc6m-7hqx-f8qxCGA-ff5q-ppvq-qr63CGA-g26q-2rjw-xjxqCGA-g3g2-hmqc-6w4wCGA-g3g5-3fx6-h739CGA-gfr5-533c-fhccCGA-grp9-r32m-x3h9CGA-hc2q-g745-fvxvCGA-hr7v-g4xr-7xxcCGA-hv9c-vq2j-crrvCGA-j2vc-g8xp-c9jqCGA-jjvh-f4c7-f428CGA-jvjg-fr5p-x76wCGA-jx25-w36x-c4r8CGA-jx7m-5xrh-hwv9CGA-mq92-v76j-vww9CGA-p548-479m-383cCGA-p6f2-ghfg-v945CGA-pgc9-2qwf-32f7CGA-phg6-9xw5-crmhCGA-224r-5g49-297cCGA-22fh-7pjw-3f3fCGA-2355-wrj5-pm8fCGA-28qx-25jp-9h93CGA-2g7c-w4gj-fvpjCGA-2hjj-c645-m6xvCGA-2mjm-xqw8-hr4vCGA-2rrr-44gx-v6vqCGA-2w4p-8328-8fppCGA-2wwm-q4p2-hhc2CGA-2x54-9wch-2v55CGA-2x8r-6r3h-2335CGA-349c-qr3p-327hCGA-35pc-pr39-6r4gCGA-36m2-3q79-rpx9CGA-37v5-3g2q-h265CGA-3h6j-7mfm-48ppCGA-3pm6-3xj3-f2mpCGA-3q7g-5w2h-j42xCGA-3x57-2p4m-3xj7CGA-45fv-6hvc-93fgCGA-4765-v5rc-8p6vCGA-4c2w-jcq3-7x8qCGA-4g27-m3rw-vpf3CGA-4hvr-x3xh-444jCGA-4j6v-4gpw-847fCGA-4v78-3659-mqf7CGA-4w8j-mjg4-rh7xCGA-4x23-65f8-mw28CGA-549p-gr7f-5rf7CGA-59m2-f786-8p4fCGA-5f6g-8328-49xxCGA-5f83-p2pf-x5ggCGA-5jr7-2c4j-c5rvCGA-5pch-9hg7-25pqCGA-5r4w-4wp7-7q43CGA-626v-rp7m-c3fjCGA-62cq-7w7m-mcvgCGA-62j6-87rg-hfh6CGA-637g-72cm-vv9qCGA-637g-v6vm-m63pCGA-665m-g3q4-82cqCGA-66c4-2rmc-w969CGA-6743-6wjh-h8fwCGA-6c2g-fvwv-4226CGA-6cfm-4v6c-rpm2CGA-6pgp-xh47-9r6pCGA-6rvc-97w7-4xc7CGA-6vq4-7vch-v6qmCGA-6xff-v2m6-chh2CGA-732m-39hj-fr78CGA-76wp-2hh3-7pf9CGA-7799-cr36-52w2CGA-77cq-67r3-3c7fCGA-77wm-g823-8fw6CGA-797q-5835-542qCGA-799x-wg93-mfx7CGA-7ff2-8wgw-jcmqCGA-7g85-pcpq-5p37CGA-7hrj-pqv6-v749CGA-7qw7-85wv-5j9qCGA-836v-23c6-977vCGA-84g9-4chx-7763CGA-87c9-g89v-8g96CGA-87ff-gcrp-c563CGA-8m82-fhw6-cg78CGA-8mg3-2gf5-4v3hCGA-8rvh-ch3v-23q9CGA-8rxp-rxq6-r3q5CGA-8wq2-g269-x3r2CGA-8x5r-qwj3-q87jCGA-93wc-94h5-8856CGA-947r-4r6p-7wgjCGA-9659-m2qv-h5xgCGA-99f6-9rfr-rq4fCGA-9ch5-fvx5-hxjhCGA-9fxp-x9q3-fmmcCGA-9hfh-xw3q-v9hcCGA-9pp4-2v25-wvj3CGA-9r67-qqr3-8fpjCGA-9rfw-f895-jgg6CGA-c559-f6r9-8c8pCGA-c56c-mp9q-853wCGA-c9mr-gg93-5mfpCGA-cf88-36p6-2jw9CGA-cj9w-x5gw-wgwcCGA-cqcx-8v9c-x647CGA-cqx7-77f7-75h9CGA-cwfg-fw5v-w454CGA-cwfm-675p-8mgvCGA-cwrc-8mx5-m6j3CGA-cxcv-r2jg-p525CGA-f5mj-3428-qhx9CGA-f624-g9fr-2584CGA-ff4p-34f9-qhvpCGA-ffwp-cgrw-fr8xCGA-fg7q-c5rr-ww5cCGA-fgxv-qhhw-2j6rCGA-fmjh-qxg6-q24xCGA-g62h-vj96-gcmjCGA-g6rf-8gxm-m3hjCGA-g7h5-r72r-v743CGA-g96m-m352-8p4gCGA-gc62-vx4x-g3vfCGA-gg98-h7mv-rjhrCGA-gq9f-cfm9-x4v6CGA-grfv-v7h7-rcqpCGA-gvpm-c295-f9c6CGA-gwxw-3h36-gf7pCGA-h2fj-g8xv-2764CGA-h2p4-67qw-23h6CGA-h3q8-99hh-mx3cCGA-h5ff-rgcf-5cqmCGA-h66v-jrqp-jpf9CGA-h8p4-gv5j-33m3CGA-h934-6j73-7p35CGA-h95w-3vjx-7c25CGA-hc99-8m7x-725mCGA-hf43-4fpg-49w5CGA-hf43-g2pq-h5xvCGA-hp8q-7hh4-gmwgCGA-hvjr-wcx8-8r94CGA-hw7j-4hxw-4wp5CGA-hwcr-v7gg-m36rCGA-j479-w5f7-9fvhCGA-j5p4-9vrc-5m77CGA-j5wj-5fj9-fpqrCGA-j6f6-34cp-8w94CGA-j7rc-jgjj-p6f7CGA-j9fr-3375-469wCGA-jcxj-h3vg-vfghCGA-jp7v-w6gr-685wCGA-jw6q-5x5f-mrg3CGA-jxmp-x2rm-xx32CGA-m2hx-6pr9-j345CGA-m6fh-83qq-x7h9CGA-m737-2f9g-825xCGA-m923-2prw-pm69CGA-m934-q96g-h2mwCGA-m9xq-vrmw-8c7jCGA-mcpj-wq3r-qx2vCGA-mpxm-7m9g-46mqCGA-mqfh-v8xm-jwjfCGA-mxvg-9w9x-xh28CGA-p2cg-7f47-rv27CGA-p39h-j3vw-rj78CGA-p3rj-vj2w-hpxwCGA-p6jr-hwr8-j86wCGA-p76v-v3g2-697hCGA-p957-j6c8-577xCGA-p95h-28wg-p26mCGA-p9w4-m345-4396CGA-pfhf-7v38-7hgcCGA-pgm9-h9qv-rpr4CGA-pjh4-4r73-7j9fCGA-ppmm-x3fm-h298CGA-pqxp-5ffr-j524CGA-pvgp-5mxf-c6pjCGA-pwhg-67c8-5cv4CGA-q29w-2xq3-m72gCGA-q42w-mgm8-34xcCGA-q4x4-6686-pm78CGA-q577-wcrr-hgxjCGA-q5hh-m64g-6qr6CGA-q76g-74g5-8xxjCGA-q995-5wh2-g25qCGA-q9g7-w8v6-v95qCGA-qcc4-ccmq-cp3pCGA-qjpx-2x5j-pvj3CGA-qmc9-p6cv-m233CGA-qmq2-645m-2pv6CGA-qqg7-gj79-xpv6CGA-qqw2-x4hv-2q58CGA-r2q4-chmg-76wgCGA-r32p-7fph-2mrvCGA-r538-qrpg-9x9mCGA-r65c-7jw7-gpr7CGA-r85w-qrv4-3j8wCGA-r94q-v225-8fcgCGA-rc98-v722-f547CGA-rfw3-mmww-hv4mCGA-rg7h-rxhv-m52fCGA-rgmc-6429-95v5CGA-rgw2-vj4r-m7fmCGA-rj7v-qcq6-hx76CGA-rmxh-9rj6-3g9xCGA-rq64-pjvc-2w6pCGA-rqp5-gpm9-r8pvCGA-rr95-qgpf-f45pCGA-v2rh-7vj7-mmjqCGA-v4hg-rmqg-gx43CGA-v5c8-4966-wvv7CGA-v6q4-v3f9-f863CGA-v944-w5gw-8v8qCGA-vcrq-746c-h5xmCGA-vq5g-x44q-mpjcCGA-vqq2-7xr8-2hfqCGA-vrgh-qjqp-rv3cCGA-vw6w-wxjf-524hCGA-vxc8-g8vw-vxrxCGA-w3x3-pc36-j87vCGA-w43f-c6w3-44r6CGA-w4cx-g2f8-6349CGA-w4jm-p84v-jvc8CGA-w96m-jqhq-88cxCGA-wgpf-rmv9-3p5jCGA-wjr2-4mg2-v8w5CGA-wrr5-r8w9-h592CGA-ww86-vw5v-6w5qCGA-wwg7-p6f6-5649CGA-x377-5f7x-rjf9CGA-x4fg-qr4m-mg9rCGA-xcf8-47xr-7p8mCGA-xfqv-gfp5-4r6pCGA-xgjv-wgpr-xpwcCGA-xmpp-34pm-ch5fCGA-xpmr-7w9p-hm9qCGA-xqfp-8fcm-778jCGA-xqqf-wjwx-9mqcCGA-xr35-qppv-gp58CGA-xw96-922m-8586CGA-xww7-mj4r-6qc4CGA-xx9m-6mv6-rxj7CGA-2qfx-xhjw-rvjvCGA-xwpv-7522-c6wgCGA-gc96-hxhv-pr43CGA-vwch-444p-5p26CGA-23p9-g9c5-j848CGA-977m-2wqf-7cwvCGA-j8vj-rf53-7c4wCGA-wg7r-6j6g-7pcxCGA-5gp3-9h9v-jcm7CGA-8c3g-8qgx-gw2pCGA-8hp5-pq6c-5v2f
Advisory lineage Upstream: 0 Downstream: 2
Awaiting Analysis
Published: 29 Aug 2026, 23:51
Last modified:31 Aug 2026, 17:08

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
6.3 MEDIUM
v4.0 (cve.org)
EPSS Score
0.26% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Aug 2026, 23:51
Published
Vulnerability first disclosed
31 Aug 2026, 17:08
Last Modified
Vulnerability information updated

Description

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is truthy, so a value such as `{ constructor: { isBuffer: "x" } }` makes the call throw `TypeError: obj.constructor.isBuffer is not a function`. ### Details `lib/stringify.js:127` calls `utils.isBuffer` on every non-primitive value it serializes. `utils.isBuffer` (`lib/utils.js:332`) reads `obj.constructor.isBuffer` and invokes it without verifying that it is a function. `constructor` and `isBuffer` are ordinary property names, so any object carrying them as own properties reaches the unchecked call. Such an object can be built from untrusted input. `qs.parse("x[constructor][isBuffer]=y", { plainObjects: true })` or `{ allowPrototypes: true }` keeps the `constructor` key as an own property (the default parse options drop it), and `JSON.parse("{\"a\":{\"constructor\":{\"isBuffer\":\"x\"}}}")` produces the same shape with no qs option involved. Express 4 with its default `query parser` setting and body-parser with `extended: true` both call `qs.parse` with `allowPrototypes: true`, so on those stacks `req.query` and `req.body` can carry the shape directly. #### PoC ```js var qs = require("qs"); qs.stringify(qs.parse("x[constructor][isBuffer]=y", { plainObjects: true })); qs.stringify(JSON.parse("{\"a\":{\"constructor\":{\"isBuffer\":\"x\"}}}")); // TypeError: obj.constructor.isBuffer is not a function // at Object.isBuffer (lib/utils.js:332:78) // at stringify (lib/stringify.js:127:45) ``` #### Fix `lib/utils.js`, applied in e83d321 on `main` and released as v6.16.0: ```diff - return !!(obj.constructor && obj.constructor.isBuffer && obj.constructor.isBuffer(obj)); + return !!(obj.constructor && typeof obj.constructor.isBuffer === "function" && obj.constructor.isBuffer(obj)); ``` Real `Buffer`, `safer-buffer`, and browserify `buffer` polyfill instances serialize exactly as before; only the throw is removed. ### Affected versions `>=2.2.5 <6.16.0`, fixed in v6.16.0. The unguarded duck-type was introduced in 3768a75 and first shipped in v2.2.5 (September 2014). v2.2.4 and earlier used `Buffer.isBuffer` and are not affected. Every release from v2.2.5 through v6.15.3 contains the unguarded call. ### Impact An unauthenticated request can make any code path that re-serializes attacker-influenced data with `qs.stringify` (for example, rebuilding a query string from `req.query` for a redirect or an upstream request, or serializing a parsed JSON body) throw synchronously. In a typical Node.js HTTP framework the throw is caught by the framework error boundary and the affected request returns a 500; the process survives and other requests are unaffected. Where the call runs outside an error boundary, such as an `async` Express 4 handler (where the throw becomes an unhandled promise rejection) or a background job, the process exits, so the impact in that case depends on the application error handling rather than on qs.

CVSS Metrics

  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS Trends

Current EPSS score: 0.26% Percentile: 18%

Techniques & Countermeasures

  • CWE-248Uncaught Exception

    An exception is thrown from a function, but it is not caught.

  • CWE-703Improper Check or Handling of Exceptional Conditions

    The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.

Affected Systems

  • chainguardarangodb-3.11

    < 3.11.14.5-r18

  • chainguardarangodb-3.12

    < 3.12.9.4-r31

  • chainguardargo-workflows-ui-4.0

    < 4.0.11-r0

  • chainguardazurite

    < 3.36.0-r4

  • chainguardcode-server

    < 4.135.0-r2

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguarddotstatsuite-supercore

    < 3.1.0_git20260903-r0

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.7-r7

  • chainguardjson-server

    all | < 0.17.4-r13

  • chainguardjupyter-base-notebook

    all

  • chainguardkibana-9.2

    all

  • chainguardkibana-9.2-iamguarded

    all

  • chainguardkibana-9.3

    all

  • chainguardkibana-9.3-iamguarded

    all

  • chainguardkibana-9.4

    < 9.4.6-r2

  • chainguardkibana-9.4-iamguarded

    < 9.4.6-r2

  • chainguardkibana-9.5

    < 9.5.3-r1

  • chainguardkibana-9.5-iamguarded

    < 9.5.3-r1

  • chainguardkubeflow-centraldashboard

    < 2.0.0-r2

  • chainguardkubescape-grype-offline-db

    all | < 0_git20250804-r6

  • chainguardlangfuse-3

    all | < 3.225.7-r1

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    all | < 3.225.7-r1

  • chainguardlangfuse-4

    < 4.27.0-r3

  • chainguardlangfuse-4-worker

    < 4.27.0-r3

  • chainguardlangfuse-fips-3

    < 3.225.5-r2

  • chainguardlangfuse-fips-3-worker

    < 3.225.5-r2

  • chainguardlangfuse-fips-4

    < 4.26.0-r1

  • chainguardlangfuse-fips-4-worker

    < 4.26.0-r1

  • chainguardopensearch-dashboards-2

    < 2.19.6-r16

  • chainguardopensearch-dashboards-2-alerting-dashboards-plugin

    < 2.19.6-r17

Showing first 50 affected entries in server-rendered view.

References (9)