Input validation error in qs - CVE-2026-2391

 

Input validation error in qs - CVE-2026-2391

Published: March 13, 2026


Vulnerability identifier: #VU123997
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-2391
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due the arrayLimit option in qs does not enforce limits for comma-separated values when comma: true is enabled. A remote attacker can pass overly large string to the application and consume all available memory resources, leading to a denial of service condition.



Affected software

qs
MongoDB Enterprise Advanced with IBM
Guardium Data Security Center (GDSC)
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Maximo Application Suite Ai Service
Rational Performance Tester
DevOps Test Performance
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Db2 Big SQL
InfoSphere Optim Archive Viewer
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Business Automation Workflow
AppDynamics NodeJS Agent
Event Streams
IBM QRadar Data Synchronization App
Fedora
nextcloud

How to mitigate CVE-2026-2391

Install updates from vendor's website.

qs - update to 6.14.2
Guardium Data Security Center (GDSC) - update to 3.8.8
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.22-sc2, 4.3.5
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.3.1
Maximo Application Suite Ai Service - update to 9.1.13
Event Streams - update to 13.0.0
DevOps Test Performance - update to 11.0.8
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.25, 16.1.3.6
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
AppDynamics NodeJS Agent - update to 25.12.1
IBM QRadar Data Synchronization App - update to 4.0.0
Db2 Big SQL - update to 8.3.1 patch 4
InfoSphere Optim Archive Viewer - update to 11.7.0.14
nextcloud - addressed in versions 33.0.1-1.el10_1, 33.0.1-1.fc42

External References

Related Security Bulletins