CVE-2026-82417

Published: Ago 30, 2026 Last Modified: Ago 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,3
Source: 7ffcee3d-2c14-4c3e-b844-86c6a321a158
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 5,3
Source: 7ffcee3d-2c14-4c3e-b844-86c6a321a158
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: low

Description

AI Translation Available

### Summary

`qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is truthy, so a value such as `{ constructor: { isBuffer: 'x' } }` makes the call throw `TypeError: obj.constructor.isBuffer is not a function`.

### Details

`lib/stringify.js:127` calls `utils.isBuffer` on every non-primitive value it serializes. `utils.isBuffer` (`lib/utils.js:332`) reads `obj.constructor.isBuffer` and invokes it without verifying that it is a function. `constructor` and `isBuffer` are ordinary property names, so any object carrying them as own properties reaches the unchecked call.

Such an object can be built from untrusted input. `qs.parse('x[constructor][isBuffer]=y', { plainObjects: true })` or `{ allowPrototypes: true }` keeps the `constructor` key as an own property (the default parse options drop it), and `JSON.parse('{\'a\':{\'constructor\':{\'isBuffer\':\'x\'}}}')` produces the same shape with no qs option involved. Express 4 with its default `query parser` setting and body-parser with `extended: true` both call `qs.parse` with `allowPrototypes: true`, so on those stacks `req.query` and `req.body` can carry the shape directly.

#### PoC

```js

var qs = require('qs');

qs.stringify(qs.parse('x[constructor][isBuffer]=y', { plainObjects: true }));

qs.stringify(JSON.parse('{\'a\':{\'constructor\':{\'isBuffer\':\'x\'}}}'));

// TypeError: obj.constructor.isBuffer is not a function

// at Object.isBuffer (lib/utils.js:332:78)

// at stringify (lib/stringify.js:127:45)

```

#### Fix

`lib/utils.js`, applied in e83d321 on `main` and released as v6.16.0:

```diff

- return !!(obj.constructor && obj.constructor.isBuffer && obj.constructor.isBuffer(obj));

+ return !!(obj.constructor && typeof obj.constructor.isBuffer === 'function' && obj.constructor.isBuffer(obj));

```

Real `Buffer`, `safer-buffer`, and browserify `buffer` polyfill instances serialize exactly as before; only the throw is removed.

### Affected versions

`>=2.2.5 <6.16.0`, fixed in v6.16.0.

The unguarded duck-type was introduced in 3768a75 and first shipped in v2.2.5 (September 2014). v2.2.4 and earlier used `Buffer.isBuffer` and are not affected. Every release from v2.2.5 through v6.15.3 contains the unguarded call.

### Impact

An unauthenticated request can make any code path that re-serializes attacker-influenced data with `qs.stringify` (for example, rebuilding a query string from `req.query` for a redirect or an upstream request, or serializing a parsed JSON body) throw synchronously. In a typical Node.js HTTP framework the throw is caught by the framework error boundary and the affected request returns a 500; the process survives and other requests are unaffected. Where the call runs outside an error boundary, such as an `async` Express 4 handler (where the throw becomes an unhandled promise rejection) or a background job, the process exits, so the impact in that case depends on the application error handling rather than on qs.

248

Uncaught Exception

Draft
Common Consequences
Security Scopes Affected:
Availability Confidentiality
Potential Impacts:
Dos: Crash, Exit, Or Restart Read Application Data
Applicable Platforms
Languages: C++, Java, C#
View CWE Details
703

Improper Check or Handling of Exceptional Conditions

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Availability Integrity
Potential Impacts:
Read Application Data Dos: Crash, Exit, Or Restart Unexpected State
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/ljharb/qs/commit/e83d321ffafb38cf210683ac31714fce6ce1c6c6
https://github.com/ljharb/qs/security/advisories/GHSA-4mjr-xmp4-gh2g