Skip to content

Fix upgrade qs from 6.14.1 to 6.15.0 to resolve CVE-2026-2391#558

Merged
jamespepper81 merged 2 commits into
mainfrom
dev
Feb 16, 2026
Merged

Fix upgrade qs from 6.14.1 to 6.15.0 to resolve CVE-2026-2391#558
jamespepper81 merged 2 commits into
mainfrom
dev

Conversation

@jamespepper81
Copy link
Copy Markdown
Contributor

No description provided.

claude and others added 2 commits February 16, 2026 11:52
Fixes Dependabot alert #30 (GHSA-w7fw-mjwx-w883): qs arrayLimit
bypass in comma parsing allows denial of service via memory exhaustion.

https://claude.ai/code/session_01NxmEtYhm33rKmBCPW8MSvq
…30-D49x8

fix: upgrade qs from 6.14.1 to 6.15.0 to resolve CVE-2026-2391
@jamespepper81 jamespepper81 merged commit f5b6eee into main Feb 16, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants