Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-32701

Опубликовано: 20 мар. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form field names during FormData parsing. By submitting mixed array-index and object-property keys for the same path, an attacker could cause user-controlled properties to be written onto values that application code expected to be arrays. When processing application/x-www-form-urlencoded or multipart/form-data requests, Qwik City converted dotted field names (e.g., items.0, items.1) into nested structures. If a path was interpreted as an array, additional attacker-supplied keys on that path—such as items.toString, items.push, items.valueOf, or items.length—could alter the resulting server-side value in unexpected ways, potentially leading to request handling failures, denial of service through malformed array state or oversized lengths, and type confusion in downstream code. This issue was fixed in version 1.19.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:qwik:qwik:*:*:*:*:*:node.js:*:*
Версия до 1.19.2 (исключая)

EPSS

Процентиль: 36%
0.00427
Низкий

7.5 High

CVSS3

Дефекты

CWE-843

Связанные уязвимости

CVSS3: 7.5
debian
5 месяцев назад

Qwik is a performance-focused JavaScript framework. Versions prior to ...

CVSS3: 7.5
github
5 месяцев назад

Qwik City has array method pollution in FormData processing allows type confusion and DoS

EPSS

Процентиль: 36%
0.00427
Низкий

7.5 High

CVSS3

Дефекты

CWE-843