Skip to content

Dev#379

Merged
jamespepper81 merged 2 commits into
mainfrom
dev
Jan 4, 2026
Merged

Dev#379
jamespepper81 merged 2 commits into
mainfrom
dev

Conversation

@jamespepper81
Copy link
Copy Markdown
Contributor

qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion fix

dependabot Bot and others added 2 commits January 4, 2026 17:31
Bumps [qs](https://github.com/ljharb/qs) from 6.14.0 to 6.14.1.
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.14.0...v6.14.1)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.14.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@jamespepper81 jamespepper81 merged commit 6340283 into main Jan 4, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant