CVE-2026-82562

Aliases:DEBIAN-CVE-2026-82562UBUNTU-CVE-2026-82562GHSA-x5fp-wj9c-mxmxCGA-323r-2mxh-v926CGA-4gwp-5vp3-4j5fCGA-4xf7-g3cp-r7c3CGA-58rj-pfw6-vr46CGA-5gw7-9hph-hfj5CGA-662v-j7m8-xgqcCGA-6wph-c9mx-52m9CGA-7wmf-m452-q7v5CGA-8w9p-f7rc-qf7wCGA-96g2-p34j-crmrCGA-975r-685h-r26jCGA-9hff-25w7-6pr6CGA-cfcv-m6jc-c2wpCGA-cqxg-wr38-r52vCGA-crhf-68fv-qj9hCGA-cv96-8229-9cj9CGA-f9w5-7c76-c7wrCGA-fjm2-c3q8-q5qpCGA-fm8h-968g-f3gpCGA-fv7v-63p3-jj5xCGA-fxqr-mf43-9mmmCGA-g5xf-72wq-hwwvCGA-h25f-hfwv-9vvgCGA-hw44-m55r-h2mrCGA-j35h-xhwr-q362CGA-j4xp-w8wj-q66fCGA-j587-h2p3-98h8CGA-jmj7-2fm7-p6jxCGA-jx64-8m32-p6r5CGA-m2fq-7526-43hfCGA-mg62-9v42-g779CGA-mmh7-5jv9-m4q6CGA-mq56-p6pm-234hCGA-mr4r-fh7h-r3r2CGA-mxp4-cp9h-vqgmCGA-p4c7-jhmw-hv36CGA-pp55-xhq4-9j8cCGA-23mv-m5vc-5m5vCGA-25vg-h74q-xxf7CGA-28cv-r948-9hw7CGA-2c7c-2h7m-hxg8CGA-2cj9-x8xh-qqw9CGA-2g8v-hc7f-68hjCGA-2hm8-g5vc-ph5qCGA-2pf9-q5rw-7p5wCGA-2q92-vq6g-h8x3CGA-2qpr-jqv4-w7q5CGA-2rxv-h7h4-xf8hCGA-2w78-cfxv-2664CGA-2xj2-qf9j-gc44CGA-33j7-7vx5-2395CGA-33w2-96vr-f57vCGA-3c59-xw2q-hfxgCGA-3g3p-89q5-q6c4CGA-3p23-43xm-mpxjCGA-3q88-h8jc-mfv6CGA-3qcc-qv3x-44c7CGA-45c9-g8j8-hmf5CGA-495v-fpvc-3cf6CGA-4cfq-c7jm-jrv5CGA-4fvj-mxjw-pg3xCGA-4jwf-q3r2-f35xCGA-4pc2-2f29-694mCGA-4rf9-7qx4-75qfCGA-52mq-h8cc-mxr7CGA-5359-xqm4-458vCGA-5478-74xg-pqwxCGA-55jq-m95x-5vjjCGA-56cm-jwhw-3w5mCGA-57h6-c8qf-j8qcCGA-59qq-86h6-7ffjCGA-5gm2-pvhg-9w3xCGA-5q5p-5gm8-496jCGA-5r38-f8mq-8583CGA-6484-ch2m-xpf4CGA-699c-5733-hhgwCGA-69xf-824w-7m6fCGA-6q3j-v42v-87j5CGA-6r5j-rg8v-mfxxCGA-6v8r-hjvm-mw66CGA-6w7h-c79q-rv4vCGA-6wrf-v3mq-9mpfCGA-732q-9mvm-ghwxCGA-769v-6p3q-mw5rCGA-778q-hqww-48h3CGA-7g4c-4jm5-2mh5CGA-7jcm-26g7-wh7rCGA-7v47-66cx-76hjCGA-7wmq-fffm-6mmqCGA-7xv7-cff2-pfpcCGA-825p-v9hr-vv7hCGA-82rc-979c-v9rxCGA-8c5r-gxvh-98mmCGA-8f5m-9rr4-w6g9CGA-8hc9-54mh-jrqwCGA-8j7p-hr4m-5xxpCGA-8r56-28vw-442qCGA-8w36-8w7r-fv5xCGA-964r-4696-v655CGA-9pcg-6rh7-793hCGA-9vcc-mww7-m628CGA-9vch-5wg8-9cfwCGA-c494-rrr8-grrwCGA-c7wx-3f3g-8ch3CGA-cmqq-rwr9-q6c2CGA-cvrp-4hqm-fv38CGA-cx9j-jcjx-2qwmCGA-f6hp-858r-xg2mCGA-f7hh-rp73-26f9CGA-f8p9-g7qj-7rfpCGA-f98c-r78r-v9fvCGA-fcqc-wf53-p9f9CGA-ff9j-jfvq-v53qCGA-ffhm-5fgc-hvrxCGA-fgfj-6vp4-xv2gCGA-fgp2-rcfh-8c3hCGA-fhrm-9xcx-93crCGA-frg4-c2f9-rgh3CGA-g6p6-wj8f-h4m6CGA-gh7g-v884-gx84CGA-gmhr-447x-hh58CGA-gpqp-7x65-rrhpCGA-h2v8-gxhr-gw2wCGA-h3pj-fp33-x3hcCGA-h46j-qvfc-jwpvCGA-h5vc-3cqj-cfx3CGA-h68p-gf98-mv74CGA-h8v7-r2wj-9xfgCGA-hcv7-rfc3-7jmvCGA-hghr-77mm-5vvrCGA-hpm4-ggcp-c4x3CGA-hpxm-59mh-vp89CGA-hq9x-x8f6-rv98CGA-hqw5-35v8-p7x3CGA-hrhr-3cgc-mc6pCGA-hv53-945f-h638CGA-hx42-c56c-hmmpCGA-j5pp-mf5q-c79pCGA-j9r3-mg7v-3f4cCGA-jj8g-875g-88hvCGA-jm7v-h642-8mf5CGA-jqcv-hj2m-5cj2CGA-jqxc-6x5r-3396CGA-jv36-g2jg-g9g8CGA-m7g2-jvjh-h4vvCGA-mr4m-h7c5-xj52CGA-mwhq-mf7v-4q9mCGA-p27c-q2g6-9r7fCGA-p2w9-j2p6-grjwCGA-p3vm-5q9g-q857CGA-p87q-7g9q-46cpCGA-pc64-5rwp-5m5cCGA-pcpv-79q3-7r5cCGA-pgv4-98gm-cpcjCGA-pj2j-h6hh-5f56CGA-q39q-5f3r-jvfwCGA-q3c8-xwr9-r545CGA-q6r8-5fv7-g6jpCGA-qgvr-vhmg-qmq5CGA-qjqf-rpfw-36wgCGA-qp4g-4vqx-cj3jCGA-qqmv-g275-cw76CGA-qrrw-5ph5-h5vmCGA-qvvw-8hh7-5wfhCGA-r5fw-8c6m-5785CGA-r5wc-44v4-3xqrCGA-r9wf-3hh9-4p6rCGA-rf9f-hp62-9crfCGA-rmfj-j982-gp37CGA-rmxj-4x3p-g3mqCGA-rqpg-5vmp-p6f6CGA-rr5f-pv44-p957CGA-rrgc-m6mx-m56jCGA-rv72-v6v9-4g4rCGA-v23q-fj52-xw38CGA-v5j6-9r25-hqwhCGA-v5rx-m482-7xg8CGA-v65v-r3h7-cq59CGA-v696-fhx5-fmmvCGA-v8vg-xq65-r237CGA-vcwx-qwr3-xgcqCGA-vfpx-5mhh-g228CGA-vhfm-qg28-chv9CGA-vjpc-p2gx-6pf9CGA-wcwv-ppgh-52rwCGA-wf35-fjjm-6j6hCGA-wf62-rcrj-r62fCGA-wfwq-v38m-rxmhCGA-wfwx-7g9h-7486CGA-wjr8-f998-6cp4CGA-wmmw-82xx-j6g8CGA-wpjv-9fr9-6rqwCGA-wr8q-xmp6-6hrjCGA-wv4m-52m9-x5fpCGA-wxmj-4g45-mj35CGA-x34g-q8rf-q9r5CGA-x429-7w96-2c5gCGA-x4j3-737v-jm75CGA-x4pf-h8h4-wfq2CGA-x733-m4jv-g6qpCGA-x8qc-mff4-668mCGA-x94j-2crv-4q5xCGA-x98w-3wjx-8298CGA-x9hq-xm6p-279wCGA-x9rf-96c5-qcpfCGA-xc24-vv6f-g46fCGA-xc4m-72x8-rhh7CGA-xh75-c2r3-58h6CGA-xv3r-ghr6-rjq8CGA-xv4c-9pv9-p634CGA-xxfm-8jpq-w63hCGA-xxj4-hrxr-v3jrCGA-4pvh-7wq6-q6v9CGA-6g32-q69v-7jgwCGA-8pxr-25mq-v8m9CGA-2xx5-7j63-vvxpCGA-3g7q-68r2-hq32CGA-79hm-6rr3-mxp5CGA-99pg-6cqq-crppCGA-6r6q-3mqj-gjr2CGA-8q42-93mq-9pqwCGA-cvjm-7fm6-j4xx
Advisory lineage Upstream: 0 Downstream: 3
Awaiting Analysis
Published: 29 Aug 2026, 23:58
Last modified:31 Aug 2026, 17:04

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
6.3 MEDIUM
v4.0 (cve.org)
EPSS Score
0.32% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Aug 2026, 23:58
Published
Vulnerability first disclosed
31 Aug 2026, 17:04
Last Modified
Vulnerability information updated

Description

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the same value under a flat key (`a=1,2,3,4`), an indexed key (`a[0]=`), a nested key (`a[b]=`), or a dotted key (`a.b=` with `allowDots`) throws the documented `RangeError`. A single parameter such as `a[]=1,2,2,...` therefore produces an inner array of arbitrary length even though the caller opted into the hard limit. This is the `[]=` key form that the fix for CVE-2026-2391 (qs 6.14.2) did not cover. ### Details In `lib/parse.js`, a comma-separated value under a `[]=` key is split and then wrapped as a single nested element (`val = [val]`, so that each `a[]=x,y` group counts as one element of the outer array). The `arrayLimit` check that 6.14.2 added for comma values runs after that wrap, so for `[]=` parts it only ever saw the wrapper of length 1. 6.15.3 added a pre-split comma count so that an oversized value throws before it is allocated, but gated it on an `isFlatArrayValue` flag that `parseValues` set to `false` for any part containing `[]=`, and did not pass it for object-valued input, so the gap remained. #### PoC ```js var qs = require('qs'); var options = { comma: true, arrayLimit: 3, throwOnLimitExceeded: true }; qs.parse('a=1,2,3,4', options); // RangeError: Array limit exceeded. Only 3 elements allowed in an array. qs.parse('a[]=1,2,3,4', options); // { a: [ [ '1', '2', '3', '4' ] ] } (no throw) qs.parse('a[]=' + '1,'.repeat(1000000) + '1', { comma: true, arrayLimit: 20, throwOnLimitExceeded: true }); // no throw; a 1,000,001-element inner array is allocated ``` #### Fix `lib/parse.js`, applied in 8859c37 on `main` and released as v6.16.0: the `isFlatArrayValue` gate is removed, so every comma-split value is counted against `arrayLimit` before splitting regardless of key form. An in-limit group under `a[]=` still counts as one element of the outer array, and the default (`throwOnLimitExceeded: false`) path is unchanged. ### Affected versions `>=6.14.2 <6.16.0`, fixed in v6.16.0. v6.14.2 introduced `arrayLimit` enforcement for comma values (the fix for CVE-2026-2391) but only for values not under a `[]=` key, and every release from v6.14.2 through v6.15.3 has the same gap. v6.14.0 and v6.14.1, where `throwOnLimitExceeded` exists but does not apply to any comma form, are covered by CVE-2026-2391 rather than this record. Earlier lines (6.7.x through 6.13.x) have `comma` but no `throwOnLimitExceeded`, so there is no hard cap on any comma path to bypass; releases before 6.7.0 have no `comma` option. ### Impact An unauthenticated attacker who can reach an application that parses untrusted query strings or urlencoded bodies with both `comma: true` and `throwOnLimitExceeded: true` (both non-default) can bypass the configured limit with a single `a[]=` parameter and force the parser to allocate an array proportional to the request size. The cost is strictly linear in the attacker-supplied bytes (about 0.1 microseconds and 6 to 7 retained bytes per input byte; the same out-of-memory threshold as the documented default `throwOnLimitExceeded: false` path), so a transport-layer request or body size limit bounds it completely (and node's default maximum HTTP header size of 16 KB already bounds the request line, so multi-megabyte payloads need a body parser). The impact is that an opt-in hard limit fails open on one key spelling, not unbounded allocation from a small input.

CVSS Metrics

  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1LOWScore: 3.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS Trends

Current EPSS score: 0.32% Percentile: 25%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • chainguardarangodb-3.12

    < 3.12.9.4-r31

  • chainguardargo-workflows-ui-4.0

    < 4.0.11-r0

  • chainguardazurite

    < 3.36.0-r4

  • chainguardcode-server

    < 4.135.0-r2

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguarddotstatsuite-supercore

    < 3.1.0_git20260903-r0

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardjson-server

    all | < 0.17.4-r13

  • chainguardkibana-9.2

    all

  • chainguardkibana-9.2-iamguarded

    all

  • chainguardkibana-9.3

    all

  • chainguardkibana-9.3-iamguarded

    all

  • chainguardkibana-9.4

    < 9.4.6-r2

  • chainguardkibana-9.4-iamguarded

    < 9.4.6-r2

  • chainguardkibana-9.5

    < 9.5.3-r1

  • chainguardkibana-9.5-iamguarded

    < 9.5.3-r1

  • chainguardkubeflow-centraldashboard

    < 2.0.0-r2

  • chainguardkubescape-grype-offline-db

    all | < 0_git20250804-r6

  • chainguardlangfuse-3

    all | < 3.225.7-r1

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    all | < 3.225.7-r1

  • chainguardlangfuse-4

    < 4.27.0-r3

  • chainguardlangfuse-4-worker

    < 4.27.0-r3

  • chainguardlangfuse-fips-3

    < 3.225.5-r2

  • chainguardlangfuse-fips-3-worker

    < 3.225.5-r2

  • chainguardlangfuse-fips-4

    < 4.26.0-r1

  • chainguardlangfuse-fips-4-worker

    < 4.26.0-r1

  • chainguardopensearch-dashboards-2

    < 2.19.6-r16

  • chainguardopensearch-dashboards-2-alerting-dashboards-plugin

    < 2.19.6-r17

  • chainguardopensearch-dashboards-2-anomaly-detection-dashboards-plugin

    < 2.19.6-r16

  • chainguardopensearch-dashboards-2-dashboards-maps

    < 2.19.6-r16

  • chainguardopensearch-dashboards-2-dashboards-notifications

    < 2.19.6-r16

  • chainguardopensearch-dashboards-2-dashboards-observability

    < 2.19.6-r16

  • chainguardopensearch-dashboards-2-dashboards-query-workbench

    < 2.19.6-r16

  • chainguardopensearch-dashboards-2-dashboards-reporting

    < 2.19.6-r17

  • chainguardopensearch-dashboards-2-dashboards-search-relevance

    < 2.19.6-r16

  • chainguardopensearch-dashboards-2-dashboards-visualizations

    < 2.19.6-r16

  • chainguardopensearch-dashboards-2-fips

    < 2.19.6-r5

  • chainguardopensearch-dashboards-2-fips-alerting-dashboards-plugin

    < 2.19.6-r6

  • chainguardopensearch-dashboards-2-fips-anomaly-detection-dashboards-plugin

    < 2.19.6-r5

  • chainguardopensearch-dashboards-2-fips-dashboards-maps

    < 2.19.6-r5

  • chainguardopensearch-dashboards-2-fips-dashboards-notifications

    < 2.19.6-r5

  • chainguardopensearch-dashboards-2-fips-dashboards-observability

    < 2.19.6-r5

Showing first 50 affected entries in server-rendered view.

References (10)