Input validation error in qs - CVE-2026-2391
Published: March 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due the arrayLimit option in qs does not enforce limits for comma-separated values when comma: true is enabled. A remote attacker can pass overly large string to the application and consume all available memory resources, leading to a denial of service condition.
Affected software
MongoDB Enterprise Advanced with IBM
Guardium Data Security Center (GDSC)
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Maximo Application Suite Ai Service
Rational Performance Tester
DevOps Test Performance
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Db2 Big SQL
InfoSphere Optim Archive Viewer
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Business Automation Workflow
AppDynamics NodeJS Agent
Event Streams
IBM QRadar Data Synchronization App
Fedora
nextcloud
How to mitigate CVE-2026-2391
Guardium Data Security Center (GDSC) - update to 3.8.8
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.22-sc2, 4.3.5
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.3.1
Maximo Application Suite Ai Service - update to 9.1.13
Event Streams - update to 13.0.0
DevOps Test Performance - update to 11.0.8
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.25, 16.1.3.6
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
AppDynamics NodeJS Agent - update to 25.12.1
IBM QRadar Data Synchronization App - update to 4.0.0
Db2 Big SQL - update to 8.3.1 patch 4
InfoSphere Optim Archive Viewer - update to 11.7.0.14
nextcloud - addressed in versions 33.0.1-1.el10_1, 33.0.1-1.fc42
External References
Related Security Bulletins
- Denial of service in qs
- Splunk AppDynamics NodeJS Agent update for third-party components
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component update for qs
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in IBM Maximo AI Service
- Multiple vulnerabilities in IBM DevOps Test Performance
- Fedora EPEL 10.1 update for nextcloud
- Fedora 42 update for nextcloud
- MongoDB Enterprise Advanced with IBM update for qs
- IBM Big SQL on Cloud Pak for Data update for qs
- Multiple vulnerabilities in IBM InfoSphere Optim Archive Viewer
- IBM Watson Discovery Cartridge update for qs
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in Platform Navigator and Automation Assets in IBM Cloud Pak for Integration
- Multiple vulnerabilities in IBM QRadar Data Synchronization App
- Multiple vulnerabilities in IBM Business Automation Workflow