Skip to content

Dependancy 'qs' security issue #2750

@RubberDucky92970

Description

@RubberDucky92970

Just got notified 'qs' library is marked as a security issue. All qs versions below 6.14.0 are affected. Patched version 6.14.1 apparently is not affected

see for more info: qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion

I was wondering, is this a legitimate issue for using the react-native-community/cli library?

└─┬ @react-native-community/cli@18.0.0
└─┬ @react-native-community/cli-server-api@18.0.0
└─┬ body-parser@1.20.3
└── qs@6.13.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionFurther information is requested

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions