{"id":"UBUNTU-CVE-2014-7191","details":"The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.","modified":"2025-07-18T16:43:05Z","published":"2014-10-19T01:55:00Z","upstream":["CVE-2014-7191"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-7191"},{"type":"REPORT","url":"https://github.com/raymondfeng/node-querystring/commit/43a604b7847e56bba49d0ce3e222fe89569354d8"},{"type":"REPORT","url":"https://nodesecurity.io/advisories/qs_dos_memory_exhaustion"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2014-7191"}],"affected":[{"package":{"name":"node-qs","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/node-qs@0.6.5-1ubuntu0.1~esm1?arch=source&distro=trusty/esm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.5-1ubuntu0.1~esm1"}]}],"versions":["0.4.2-1","0.6.5-1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_name":"node-qs","binary_version":"0.6.5-1ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-7191.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}