The qs module prior to 1.0.0 in Node.js does not call the compact function for array data, which allows remote malicious users to cause a denial of service (memory consumption) by using a large index value to create a sparse array.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
nodejs node.js |