<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:34:02 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1233 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</link>
      <description>certfr-2026-avi-1233</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-KI47469 — ### Summary



`qs</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ki47469</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the langfuse package. ### Summary `qs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the langfuse package. ### Summary `qs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ki47469</guid>
    </item>
    <item>
      <title>EUVD-2026-361967</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-361967</link>
      <description>EUVD-2026-361967</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-361967</guid>
    </item>
    <item>
      <title>fkie_cve-2026-82417</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-82417</link>
      <description>&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is truthy, so a value such as `{ constructor: { isBuffer: &amp;#34;x&amp;#34; } }` makes the call throw `TypeError: obj.constructor.isBuffer is not a function`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`lib/stringify.js:127` calls `utils.isBuffer` on every non-primitive value it serializes. `utils.isBuffer` (`lib/utils.js:332`) reads `obj.constructor.isBuffer` and invokes it without verifying that it is a function. `constructor` and `isBuffer` are ordinary property names, so any object carrying them as own properties reaches the unchecked call.&lt;/p&gt;
&lt;p&gt;Such an object can be built from untrusted input. `qs.parse(&amp;#34;x[constructor][isBuffer]=y&amp;#34;, { plainObjects: true })` or `{ allowPrototypes: true }` keeps the `constructor` key as an own property (the default parse options drop it), and `JSON.parse(&amp;#34;{\&amp;#34;a\&amp;#34;:{\&amp;#34;constructor\&amp;#34;:{\&amp;#34;isBuffer\&amp;#34;:\&amp;#34;x\&amp;#34;}}}&amp;#34;)` produces the same shape with no qs option involved. Express 4 with its default `query parser` setting and body-parser with `extended: true` both call `qs.parse` with `allowPrototypes: true`, so on those stacks `req.query` and `req.body` can carry the shape directly.&lt;/p&gt;
&lt;p&gt;#### PoC&lt;/p&gt;
&lt;p&gt;```js&lt;/p&gt;
&lt;p&gt;var qs = require(&amp;#34;qs&amp;#34;);&lt;/p&gt;
&lt;p&gt;qs.stringify(qs.parse(&amp;#34;x[constructor][isBuffer]=y&amp;#34;, { plainObjects: true }));&lt;/p&gt;
&lt;p&gt;qs.stringify…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is truthy, so a value such as `{ constructor: { isBuffer: &amp;#34;x&amp;#34; } }` makes the call throw `TypeError: obj.constructor.isBuffer is not a function`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`lib/stringify.js:127` calls `utils.isBuffer` on every non-primitive value it serializes. `utils.isBuffer` (`lib/utils.js:332`) reads `obj.constructor.isBuffer` and invokes it without verifying that it is a function. `constructor` and `isBuffer` are ordinary property names, so any object carrying them as own properties reaches the unchecked call.&lt;/p&gt;
&lt;p&gt;Such an object can be built from untrusted input. `qs.parse(&amp;#34;x[constructor][isBuffer]=y&amp;#34;, { plainObjects: true })` or `{ allowPrototypes: true }` keeps the `constructor` key as an own property (the default parse options drop it), and `JSON.parse(&amp;#34;{\&amp;#34;a\&amp;#34;:{\&amp;#34;constructor\&amp;#34;:{\&amp;#34;isBuffer\&amp;#34;:\&amp;#34;x\&amp;#34;}}}&amp;#34;)` produces the same shape with no qs option involved. Express 4 with its default `query parser` setting and body-parser with `extended: true` both call `qs.parse` with `allowPrototypes: true`, so on those stacks `req.query` and `req.body` can carry the shape directly.&lt;/p&gt;
&lt;p&gt;#### PoC&lt;/p&gt;
&lt;p&gt;```js&lt;/p&gt;
&lt;p&gt;var qs = require(&amp;#34;qs&amp;#34;);&lt;/p&gt;
&lt;p&gt;qs.stringify(qs.parse(&amp;#34;x[constructor][isBuffer]=y&amp;#34;, { plainObjects: true }));&lt;/p&gt;
&lt;p&gt;qs.stringify…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-82417</guid>
    </item>
    <item>
      <title>GHSA-4mjr-xmp4-gh2g — qs: Denial of Service via Attacker Controlled isBuffer</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4mjr-xmp4-gh2g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: qs&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`qs.stringify()` calls `utils.isBuffer()` on every value it serializes, and `utils.isBuffer()` invokes `obj.constructor.isBuffer(obj)` without checking that it is callable. A value whose own `constructor.isBuffer` is a non-function makes `qs` call a non-callable and throw `TypeError`. Such a value is produced **by `qs.parse` itself** from an untrusted query string when `plainObjects: true` or `allowPrototypes: true` is set, so a pure-`qs` `parse` → `stringify` round-trip — no `JSON.parse` — turns an unauthenticated query string into an uncaught throw.&lt;/p&gt;
&lt;p&gt;An attacker-controlled `parse` input reaches the host application&amp;#39;s availability asset — via `qs`&amp;#39;s own recommended `plainObjects` mitigation — and triggers an uncaught exception during a `parse` → `stringify` round-trip.&lt;/p&gt;
&lt;p&gt;### Details
`utils.isBuffer` runs at `lib/stringify.js:127` for every serialized value:&lt;/p&gt;
&lt;p&gt;```js
if (isNonNullishPrimitive(obj) || utils.isBuffer(obj)) { ... }
```&lt;/p&gt;
&lt;p&gt;`utils.isBuffer` (`lib/utils.js:327-333`) invokes `obj.constructor.isBuffer` without verifying it is callable:&lt;/p&gt;
&lt;p&gt;```js
var isBuffer = function isBuffer(obj) {
    if (!obj || typeof obj !== &amp;#39;object&amp;#39;) { return false; }
    return !!(obj.constructor &amp;amp;&amp;amp; obj.constructor.isBuffer &amp;amp;&amp;amp; obj.constructor.isBuffer(obj));
};
```&lt;/p&gt;
&lt;p&gt;`constructor` and `isBuffer` are ordinary keys. `qs.parse` with `plainObjects: true` or `allowPrototypes: true` keeps them as own properties, so the parsed value carries a non-function `constructor.isBuffer`; `stringify` th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: qs&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`qs.stringify()` calls `utils.isBuffer()` on every value it serializes, and `utils.isBuffer()` invokes `obj.constructor.isBuffer(obj)` without checking that it is callable. A value whose own `constructor.isBuffer` is a non-function makes `qs` call a non-callable and throw `TypeError`. Such a value is produced **by `qs.parse` itself** from an untrusted query string when `plainObjects: true` or `allowPrototypes: true` is set, so a pure-`qs` `parse` → `stringify` round-trip — no `JSON.parse` — turns an unauthenticated query string into an uncaught throw.&lt;/p&gt;
&lt;p&gt;An attacker-controlled `parse` input reaches the host application&amp;#39;s availability asset — via `qs`&amp;#39;s own recommended `plainObjects` mitigation — and triggers an uncaught exception during a `parse` → `stringify` round-trip.&lt;/p&gt;
&lt;p&gt;### Details
`utils.isBuffer` runs at `lib/stringify.js:127` for every serialized value:&lt;/p&gt;
&lt;p&gt;```js
if (isNonNullishPrimitive(obj) || utils.isBuffer(obj)) { ... }
```&lt;/p&gt;
&lt;p&gt;`utils.isBuffer` (`lib/utils.js:327-333`) invokes `obj.constructor.isBuffer` without verifying it is callable:&lt;/p&gt;
&lt;p&gt;```js
var isBuffer = function isBuffer(obj) {
    if (!obj || typeof obj !== &amp;#39;object&amp;#39;) { return false; }
    return !!(obj.constructor &amp;amp;&amp;amp; obj.constructor.isBuffer &amp;amp;&amp;amp; obj.constructor.isBuffer(obj));
};
```&lt;/p&gt;
&lt;p&gt;`constructor` and `isBuffer` are ordinary keys. `qs.parse` with `plainObjects: true` or `allowPrototypes: true` keeps them as own properties, so the parsed value carries a non-function `constructor.isBuffer`; `stringify` th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4mjr-xmp4-gh2g</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-82417 — qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-82417</link>
      <description>msrc_CVE-2026-82417</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-82417</guid>
    </item>
    <item>
      <title>RHSA-2026:62544 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:62544</link>
      <description>&lt;p&gt;qs: qs: Denial of Service via improper validation in stringify function qs: qs: Denial of Service via array limit bypass in query string parsing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;qs: qs: Denial of Service via improper validation in stringify function qs: qs: Denial of Service via array limit bypass in query string parsing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:62544</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-82417</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-82417</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-qs, Ubuntu:16.04:LTS: node-qs, Ubuntu:18.04:LTS: node-qs, Ubuntu:Pro:20.04:LTS: node-qs, Ubuntu:22.04:LTS: node-qs, Ubuntu:24.04:LTS: node-qs, Ubuntu:26.04:LTS: node-qs&lt;/p&gt;
&lt;p&gt;### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is truthy, so a value such as `{ constructor: { isBuffer: &amp;#34;x&amp;#34; } }` makes the call throw `TypeError: obj.constructor.isBuffer is not a function`. ### Details `lib/stringify.js:127` calls `utils.isBuffer` on every non-primitive value it serializes. `utils.isBuffer` (`lib/utils.js:332`) reads `obj.constructor.isBuffer` and invokes it without verifying that it is a function. `constructor` and `isBuffer` are ordinary property names, so any object carrying them as own properties reaches the unchecked call. Such an object can be built from untrusted input. `qs.parse(&amp;#34;x[constructor][isBuffer]=y&amp;#34;, { plainObjects: true })` or `{ allowPrototypes: true }` keeps the `constructor` key as an own property (the default parse options drop it), and `JSON.parse(&amp;#34;{\&amp;#34;a\&amp;#34;:{\&amp;#34;constructor\&amp;#34;:{\&amp;#34;isBuffer\&amp;#34;:\&amp;#34;x\&amp;#34;}}}&amp;#34;)` produces the same shape with no qs option involved. Express 4 with its default `query parser` setting and body-parser with `extended: true` both call `qs.parse` with `allowPrototypes: true`, so on those stacks `req.query` and `req.body` can carry the shape directly. #### PoC ```js var qs = require(&amp;#34;qs&amp;#34;); qs.stringify(qs.parse(&amp;#34;x[constructor][isBuffer]=y&amp;#34;, { plainObjects: true })); qs.stringify(JSON.parse(&amp;#34;{\&amp;#34;a\&amp;#34;:{\&amp;#34;cons…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-qs, Ubuntu:16.04:LTS: node-qs, Ubuntu:18.04:LTS: node-qs, Ubuntu:Pro:20.04:LTS: node-qs, Ubuntu:22.04:LTS: node-qs, Ubuntu:24.04:LTS: node-qs, Ubuntu:26.04:LTS: node-qs&lt;/p&gt;
&lt;p&gt;### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is truthy, so a value such as `{ constructor: { isBuffer: &amp;#34;x&amp;#34; } }` makes the call throw `TypeError: obj.constructor.isBuffer is not a function`. ### Details `lib/stringify.js:127` calls `utils.isBuffer` on every non-primitive value it serializes. `utils.isBuffer` (`lib/utils.js:332`) reads `obj.constructor.isBuffer` and invokes it without verifying that it is a function. `constructor` and `isBuffer` are ordinary property names, so any object carrying them as own properties reaches the unchecked call. Such an object can be built from untrusted input. `qs.parse(&amp;#34;x[constructor][isBuffer]=y&amp;#34;, { plainObjects: true })` or `{ allowPrototypes: true }` keeps the `constructor` key as an own property (the default parse options drop it), and `JSON.parse(&amp;#34;{\&amp;#34;a\&amp;#34;:{\&amp;#34;constructor\&amp;#34;:{\&amp;#34;isBuffer\&amp;#34;:\&amp;#34;x\&amp;#34;}}}&amp;#34;)` produces the same shape with no qs option involved. Express 4 with its default `query parser` setting and body-parser with `extended: true` both call `qs.parse` with `allowPrototypes: true`, so on those stacks `req.query` and `req.body` can carry the shape directly. #### PoC ```js var qs = require(&amp;#34;qs&amp;#34;); qs.stringify(qs.parse(&amp;#34;x[constructor][isBuffer]=y&amp;#34;, { plainObjects: true })); qs.stringify(JSON.parse(&amp;#34;{\&amp;#34;a\&amp;#34;:{\&amp;#34;cons…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-82417</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3498 — Red Hat OpenShift Container Platform (opentelemetry-go, qs.stringify): Mehrere Schwachstellen ermöglichen Denial of Ser…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3498</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Container Platform ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Container Platform ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3498</guid>
    </item>
  </channel>
</rss>
