Lucene search

K
osvGoogleOSV:GHSA-JJV7-QPX3-H62Q
HistoryOct 24, 2017 - 6:33 p.m.

Denial-of-Service Memory Exhaustion in qs

2017-10-2418:33:36
Google
osv.dev
13

0.053 Low

EPSS

Percentile

93.1%

Versions prior to 1.0 of qs are affected by a denial of service condition. This condition is triggered by parsing a crafted string that deserializes into very large sparse arrays, resulting in the process running out of memory and eventually crashing.

Recommendation

Update to version 1.0.0 or later.

CPENameOperatorVersion
qslt1.0.0