Vulnerability GHSA-hx4r-w6wj-j8fg
Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 hour ago
October 01, 2026 at 03:17 PM UTC
devalue: Residual sparse-array CPU amplification in uneval
1.0.0 - 5.9.2
1.0.0 - 5.9.2
Summary
devalue: Residual sparse-array CPU amplification in uneval
Details
uneval performs synchronous work proportional to a sparse array's declared length. An application that passes attacker-influenced sparse values to uneval can suffer event-loop blocking. Since attacker-controlled creation of sparse arrays is so difficult, this vulnerability is very difficult to exploit.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
1 hour ago
devalue: `stringify`/`uneval` serialize shared memory
5.1.0 - 5.9.2 GHSA-j22f-vq7h-c4qm
5.1.0 - 5.9.2 GHSA-j22f-vq7h-c4qm
High Risk
1 hour ago
devalue: Repeated primitive strings cause quadratic expansion in uneval
1.0.0 - 5.9.2 GHSA-mcm9-63f2-9j32
1.0.0 - 5.9.2 GHSA-mcm9-63f2-9j32
Low Risk
1 hour ago
devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
1.0.0 - 5.9.2 GHSA-wf3x-273g-mvxv
1.0.0 - 5.9.2 GHSA-wf3x-273g-mvxv
High Risk
2 hours ago
devalue: Custom ArrayBuffer revivers can bypass typed-array allocation validation
1.0.0 - 5.9.2 GHSA-r9w8-h9r3-54w4
1.0.0 - 5.9.2 GHSA-r9w8-h9r3-54w4
High Risk
2 hours ago
devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
5.8.0 - 5.9.2 GHSA-x5rw-q4pp-hg5g
5.8.0 - 5.9.2 GHSA-x5rw-q4pp-hg5g
Impacted packages
Timeline
Published
1 hour ago
October 01, 2026 at 03:17 PM UTC
Fixed (5.9.3)
Unknown
Unknown
Last Modified
1 hour ago
October 01, 2026 at 03:30 PM UTC