CVE-2022-24999 is a prototype-poisoning vulnerability in the qs query-string parser. In vulnerable qs releases before 6.10.3, attacker-controlled parameters using proto properties together with a large length value can manipulate parsing behavior and cause the Node.js process serving an Express application to hang. Express releases before 4.17.3 may be affected when they include a vulnerable qs dependency.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides proof-of-concept exploits for CVE-2022-24999, a vulnerability in the 'qs' JavaScript library (and by extension, Express.js) that allows prototype pollution via crafted query strings. The exploit demonstrates how an attacker can create array-like objects with a massive 'length' property by injecting '__proto__' properties into query parameters. When the application subsequently performs native array operations (such as 'indexOf' or string concatenation) on these polluted objects, the Node.js process can freeze or become unresponsive, resulting in a Denial of Service (DoS). The repository is organized into three main directories: - 'express-qs-array-bomb' and 'express-qs-string-bomb' each contain a minimal Express server (poc.js), payload files, and test scripts to demonstrate the attack via GET and POST requests. The payloads exploit the vulnerability by sending specially crafted query strings or POST bodies to the local server at http://localhost:3000/. - 'qs-vulns' contains standalone JavaScript scripts that demonstrate various prototype pollution and type confusion scenarios using the 'qs' library directly, including array bombs, string bombs, and ghost values. The exploit is effective against Node.js applications using vulnerable versions of 'qs' and Express with default configurations. The main impact is application-level DoS. No external endpoints or IPs are targeted; all tests are performed against a local server. The code is written in JavaScript and is intended for research and demonstration purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prototype pollution vulnerability in the Node.js 'qs' querystring parsing library that can allow attacker-controlled properties to be injected into object prototypes under certain unsafe merge/parse patterns.
A prototype-poisoning vulnerability in the qs component used by Express that can cause a Node.js process to hang, addressed in the Migration Toolkit for Applications 6.0.1 security update.
Prototype-poisoning issue in Express's qs component that can hang a Node.js process.
Prototype-poisoning vulnerability in the qs component used by Express that can hang the Node.js process.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.