CVE-2026-8723General

MEDIUMCVSS 6.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`). ### Details In the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining: ```js obj = utils.maybeMap(obj, encoder); ``` `utils.encode` (`lib/utils.js:195`) reads `str.length` with no null guard, so a `null` or `undefined` element throws `TypeError`. `skipNulls` and `strictNullHandling` are both checked in the per-element loop below this line and never get a chance to run. Same class of bug as the filter-array path fixed in 0c180a4. The vulnerable shape of the comma + `encodeValuesOnly` branch was introduced in 4c4b23d ("encode comma values more consistently", PR #463, 2023-01-19), first released in v6.11.1. #### PoC ```js const qs = require('qs'); qs.stringify({ a: [null, 'b'] }, { arrayFormat: 'comma', encodeValuesOnly: true }); qs.stringify({ a: [undefined, 'b'] }, { arrayFormat: 'comma', encodeValuesOnly: true }); qs.stringify({ a: [null] }, { arrayFormat: 'comma', encodeValuesOnly: true }); // TypeError: Cannot read properties of null (reading 'length') // at encode (lib/utils.js:195:13) // at Object.maybeMap (lib/utils.js:322:37) // at stringify (lib/stringify.js:145:25) ``` #### Fix `lib/stringify.js:145`, applied in 21f80b3 on `main` and released as v6.15.2: ```diff - obj = utils.maybeMap(obj, encoder); + obj = utils.maybeMap(obj, function (v) { + return v == null ? v : encoder(v); + }); ``` `null` and `undefined` now pass through `maybeMap` unchanged and reach the `join(',')` step as-is. For `{ a: [null, 'b'] }` this produces `a=,b`, matching the non-`encodeValuesOnly` comma path (which already joins before encoding and produces `a=%2Cb` for the same input). Single-element `[null]` arrays still collapse via the existing `obj.join(',') || null` and remain subject to `skipNulls` / `strictNullHandling` in the main loop. ### Affected versions `>=6.11.1 <6.15.2` — fixed in v6.15.2. The vulnerable code shape was introduced in 4c4b23d and first shipped in v6.11.1. Earlier versions — including all of 6.7.x, 6.8.x, 6.9.x, 6.10.x, and 6.11.0 — implemented the comma + `encodeValuesOnly` path differently (joining before encoding) and are not affected. Empirically verified across released versions. ### Impact Application code that calls `qs.stringify` with both `arrayFormat: 'comma'` and `encodeValuesOnly: true` (both non-default) on input that may contain a `null` or `undefined` array element will throw synchronously instead of producing a query string. In a typical Node.js HTTP framework (Express, Fastify, Koa, hapi) the sync throw is caught by the framework's error boundary and the affected request returns a 500; the worker process does not exit and subsequent requests are unaffected. The "kills the worker process" framing applies only to call sites outside a request-handler error boundary (background jobs, startup paths, stream pipelines) or to deployments with framework error handling explicitly disabled. The vulnerable input is a `null` or `undefined` entry inside an array; this is reachable from JSON request bodies or from application code constructing arrays from user input, but not from standard HTML form submissions (which produce strings or omitted fields, not literal `null`).

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-17); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-17: 2Mentions · 2026-05-24: 1Mentions · 2026-06-24: 1Active Exploitation · 2026-05-24: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-05-17: 105-1705-2406-24
Signal classification3 categories
General
250.0%
Active Exploitation
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-172
General2
2026-05-241
Active Exploitation1
2026-06-241
Patch1
Full discourse4 posts
  • RazzReport@RazzReport
    Patch

    @LiteLLM @vllm_project OpenHands/OpenHands: four CVEs patched in coordinated response - CVE-2026-54283, CVE-2026-8723, CVE-2026-41691, GHSA-jm82-fx9c-mx94. Security branches pushed simultaneously this window. Self-hosted agent runtime operators should patch before release propagates.

    Post summary

    Four CVEs, including CVE-2026-54283, CVE-2026-8723, CVE-2026-41691, and GHSA-jm82-fx9c-mx94, were patched in a coordinated release; users are urged to apply the security patches promptly.

    1000052
    14 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Active Exploitation

    Recent exploits: Critical NGINX vulnerability (CVE-2026-42945) active. Also, TLS backends allowing rogue CA cert loading (CVE-2026-8723) &amp; Google API keys lingering post-deletion threaten data integrity in transit. #Cybersecurity #News #Vulnerabilities

    Post summary

    The tweet asserts that CVE-2026-42945 is currently being exploited, while also noting a separate TLS-related vulnerability (CVE-2026-8723) that could compromise data integrity.

    0000084
    14 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-8723 ### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The … https://www.cve.org/CVERecord?id=CVE-2026-8723

    Post summary

    The announcement notes that `qs.stringify` can throw a TypeError when called with specific options on an array containing null or undefined, providing a technical detail of the reported vulnerability.

    00000208
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-8723 TypeError in qs.stringify With Comma ArrayFormat and encodeValuesOnly Opt... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8723 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A brief announcement of CVE-2026-8723, noting a TypeError in qs.stringify, includes links to vulnerability details and a notification but provides no in-depth technical information or actionable guidance.

    0000073
    4.0K followersView on X

Explore more