Vulnerability GHSA-mcm9-63f2-9j32

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
1 hour ago
October 01, 2026 at 03:17 PM UTC
devalue: Repeated primitive strings cause quadratic expansion in uneval
1.0.0 - 5.9.2
1.0.0 - 5.9.2

Summary

devalue: Repeated primitive strings cause quadratic expansion in uneval

Details

Under very constrained circumstances, data that was parsed and then passed to uneval could turn a small payload into a very large serialized string.

Impacted packages

Timeline

Published
1 hour ago
October 01, 2026 at 03:17 PM UTC
Fixed (5.9.3)
Unknown
Unknown
Last Modified
1 hour ago
October 01, 2026 at 03:30 PM UTC