---
title: "CVE-2026-2391\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-2391?format=md
keywords: index, follow
---

# CVE-2026-2391

Publication date 12 February 2026

Last updated 10 July 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**3.7 · Low**

[Score breakdown](https://ubuntu.com/security/CVE-2026-2391?format=md#impact-score)

Toggle side navigation

## Description

### Summary
The `arrayLimit` option in qs does not enforce limits for comma-separated
values when `comma: true` is enabled, allowing attackers to cause
denial-of-service via memory exhaustion. This is a bypass of the array
limit enforcement, similar to the bracket notation bypass addressed in
GHSA-6rw7-vpxm-498p (CVE-2025-15284).
### Details
When the `comma` option is set to `true` (not the default, but configurable
in applications), qs allows parsing comma-separated strings as arrays
(e.g., `?param=a,b,c` becomes `['a', 'b', 'c']`). However, the limit check
for `arrayLimit` (default: 20) and the optional throwOnLimitExceeded occur
after the comma-handling logic in `parseArrayValue`, enabling a bypass.
This permits creation of arbitrarily large arrays from a single parameter,
leading to excessive memory allocation.
\*\*Vulnerable code\*\* (lib/parse.js: lines ~40-50):
```js
if (val && typeof val === 'string' && options.comma && val.indexOf(',') >
-1) {
    return val.split(',');
}
if (options.throwOnLimitExceeded && currentArrayLength >=
options.arrayLimit) {
    throw new RangeError('Array limit exceeded. Only ' + options.arrayLimit
+ ' element' + (options.arrayLimit === 1 ? '' : 's') + ' allowed in an
array.');
}
return val;
```
The `split(',')` returns the array immediately, skipping the subsequent
limit check. Downstream merging via `utils.combine` does not prevent
allocation, even if it marks overflows for sparse arrays.This discrepancy
allows attackers to send a single parameter with millions of commas (e.g.,
`?param=,,,,,,,,...`), allocating massive arrays in memory without
triggering limits. It bypasses the intent of `arrayLimit`, which is
enforced correctly for indexed (`a[0]=`) and bracket (`a[]=`) notations
(the latter fixed in v6.14.1 per GHSA-6rw7-vpxm-498p).
### PoC
\*\*Test 1 - Basic bypass:\*\*
```
npm install qs
```
```js
const qs = require('qs');
const payload = 'a=' + ','.repeat(25); // 26 elements after split
(bypasses arrayLimit: 5)
const options = { comma: true, arrayLimit: 5, throwOnLimitExceeded: true };
try {
  const result = qs.parse(payload, options);
  console.log(result.a.length); // Outputs: 26 (bypass successful)
} catch (e) {
  console.log('Limit enforced:', e.message); // Not thrown
}
```
\*\*Configuration:\*\*
- `comma: true`
- `arrayLimit: 5`
- `throwOnLimitExceeded: true`
Expected: Throws "Array limit exceeded" error.
Actual: Parses successfully, creating an array of length 26.
### Impact
Denial of Service (DoS) via memory exhaustion.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| node-qs | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:

CVSS v4.0

[CVSS v4.0](https://ubuntu.com/security/CVE-2026-2391?format=md)
[CVSS v3.0](https://ubuntu.com/security/CVE-2026-2391?format=md)

**Base score**

6.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Attack requirements | Present |
  | Privileges required | None |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | None |
  | Vulnerable system - Integrity impact | None |
  | Vulnerable system - Availability impact | Low |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.3 · Medium |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2391)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-2391)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-2391)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-2391)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-2391>
* <https://github.com/ljharb/qs/security/advisories/GHSA-w7fw-mjwx-w883>
* <https://github.com/ljharb/qs/commit/f6a7abff1f13d644db9b05fe4f2c98ada6bf8482>
