{"api_version":"v1","generated_at":"2026-10-08T10:45:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-ljharb-qs-c15124eec3a4","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/qs","name":"qs","next_cursor":null,"observations":[{"affected":"qs: 6.14.2 < 6.16.0","affected_versions_present":true,"cve_id":"CVE-2026-82562","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82562","fixed":"Upgrade to qs 6.16.0 or later.","last_modified":"2026-08-31T17:04:14.950Z","patch_url":"https://github.com/ljharb/qs/commit/8859c37470e11b42b547b275e4e9bd0bc8cc5464","primary_source":"","published":"2026-08-29T23:58:31.289Z"},{"affected":"qs: 2.2.5 < 6.16.0","affected_versions_present":true,"cve_id":"CVE-2026-82417","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82417","fixed":"Upgrade to qs 6.16.0 or later.","last_modified":"2026-08-31T17:08:24.074Z","patch_url":"https://github.com/ljharb/qs/commit/e83d321ffafb38cf210683ac31714fce6ce1c6c6","primary_source":"","published":"2026-08-29T23:51:27.634Z"},{"affected":"6.11.1 < 6.15.2","affected_versions_present":true,"cve_id":"CVE-2026-8723","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-8723","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/","last_modified":"2026-05-18T14:02:57.825Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-8723","primary_source":"","published":"2026-05-16T23:21:16.035Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"ljharb"}}
