CVE-2026-82562: qs.parse does not enforce arrayLimit on comma groups under bracket-push keys when throwOnLimitExceeded is set (incomplete fix for CVE-2026-2391)

Published Aug 29, 2026
·
Updated

Summary

When qs.parse is called with comma: true and throwOnLimitExceeded: true, a comma-separated value under a bracket-push key (a[]=1,2,3,4) is split into an array without being compared against arrayLimit, while the same value under a flat key (a=1,2,3,4), an indexed key (a[0]=), a nested key (a[b]=), or a dotted key (a.b= with allowDots) throws the documented RangeError. A single parameter such as a[]=1,2,2,... therefore produces an inner array of arbitrary length even though the caller opted into the hard limit. This is the []= key form that the fix for CVE-2026-2391 (qs 6.14.2) did not cover.

Details

In lib/parse.js, a comma-separated value under a []= key is split and then wrapped as a single nested element (val = [val], so that each a[]=x,y group counts as one element of the outer array). The arrayLimit check that 6.14.2 added for comma values runs after that wrap, so for []= parts it only ever saw the wrapper of length 1. 6.15.3 added a pre-split comma count so that an oversized value throws before it is allocated, but gated it on an isFlatArrayValue flag that parseValues set to false for any part containing []=, and did not pass it for object-valued input, so the gap remained.

PoC

js

var qs = require('qs');

var options = { comma: true, arrayLimit: 3, throwOnLimitExceeded: true };

qs.parse('a=1,2,3,4', options); // RangeError: Array limit exceeded. Only 3 elements allowed in an array.

qs.parse('a[]=1,2,3,4', options); // { a: [ [ '1', '2', '3', '4' ] ] } (no throw)

qs.parse('a[]=' + '1,'.repeat(1000000) + '1', { comma: true, arrayLimit: 20, throwOnLimitExceeded: true });

// no throw; a 1,000,001-element inner array is allocated

Fix

lib/parse.js, applied in 8859c37 on main and released as v6.16.0: the isFlatArrayValue gate is removed, so every comma-split value is counted against arrayLimit before splitting regardless of key form. An in-limit group under a[]= still counts as one element of the outer array, and the default (throwOnLimitExceeded: false) path is unchanged.

Affected versions

>=6.14.2 <6.16.0, fixed in v6.16.0.

v6.14.2 introduced arrayLimit enforcement for comma values (the fix for CVE-2026-2391) but only for values not under a []= key, and every release from v6.14.2 through v6.15.3 has the same gap. v6.14.0 and v6.14.1, where throwOnLimitExceeded exists but does not apply to any comma form, are covered by CVE-2026-2391 rather than this record. Earlier lines (6.7.x through 6.13.x) have comma but no throwOnLimitExceeded, so there is no hard cap on any comma path to bypass; releases before 6.7.0 have no comma option.

Impact

An unauthenticated attacker who can reach an application that parses untrusted query strings or urlencoded bodies with both comma: true and throwOnLimitExceeded: true (both non-default) can bypass the configured limit with a single a[]= parameter and force the parser to allocate an array proportional to the request size. The cost is strictly linear in the attacker-supplied bytes (about 0.1 microseconds and 6 to 7 retained bytes per input byte; the same out-of-memory threshold as the documented default throwOnLimitExceeded: false path), so a transport-layer request or body size limit bounds it completely (and node's default maximum HTTP header size of 16 KB already bounds the request line, so multi-megabyte payloads need a body parser). The impact is that an opt-in hard limit fails open on one key spelling, not unbounded allocation from a small input.

Affected Software

1 affected component
Vulnerable qs>=6.14.2<6.16.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade qs to a version that resolves this vulnerability.

    Fixed in 6.16.0
  2. Compensating control

    Add/ensure a transport-layer request size/body-size limit for applications that parse untrusted query strings or urlencoded bodies with `comma: true` and `throwOnLimitExceeded: true` (the described allocation is linear in attacker-supplied bytes and is bounded by request/body size limits).

Event History

Aug 29, 2026
CVE Published
via MITRE·11:58 PM
Data Sourced
via MITRE·11:58 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments are exposed when they call qs.parse with both comma: true and throwOnLimitExceeded: true, and process bracket-push parameters in the a[]=value form. The bypass applies when the comma-separated value exceeds the configured arrayLimit.

2

What input is required to trigger the issue?

An attacker needs to supply a single bracket-push parameter whose value contains more comma-separated items than arrayLimit permits, such as a[]=1,2,3,4. The same limit enforcement is described as working for flat, indexed, nested, and dotted key forms.

3

What is the practical impact?

The parser can create an inner array of arbitrary length despite the caller having enabled the hard array limit. The reported impact is limited to availability; no confidentiality or integrity impact is indicated.

4

How can I determine whether my configuration is affected?

Parse an a[]= value containing more comma-separated entries than your configured arrayLimit while comma and throwOnLimitExceeded are enabled. An affected configuration does not throw the documented RangeError for that bracket-push input.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203