Vulnerability GHSA-hx4r-w6wj-j8fg

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 hour ago
October 01, 2026 at 03:17 PM UTC
devalue: Residual sparse-array CPU amplification in uneval
1.0.0 - 5.9.2
1.0.0 - 5.9.2

Summary

devalue: Residual sparse-array CPU amplification in uneval

Details

uneval performs synchronous work proportional to a sparse array's declared length. An application that passes attacker-influenced sparse values to uneval can suffer event-loop blocking. Since attacker-controlled creation of sparse arrays is so difficult, this vulnerability is very difficult to exploit.

Impacted packages

Timeline

Published
1 hour ago
October 01, 2026 at 03:17 PM UTC
Fixed (5.9.3)
Unknown
Unknown
Last Modified
1 hour ago
October 01, 2026 at 03:30 PM UTC