Vulnerability GHSA-r9w8-h9r3-54w4
High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 01, 2026 at 03:15 PM UTC
devalue: Custom ArrayBuffer revivers can bypass typed-array allocation validation
1.0.0 - 5.9.2
1.0.0 - 5.9.2
Summary
devalue: Custom ArrayBuffer revivers can bypass typed-array allocation validation
Details
Under very specific circumstances, parse could create massive ArrayBuffers with very small input. This required a malformed ArrayBuffer custom reviver.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
1 hour ago
devalue: `stringify`/`uneval` serialize shared memory
5.1.0 - 5.9.2 GHSA-j22f-vq7h-c4qm
5.1.0 - 5.9.2 GHSA-j22f-vq7h-c4qm
Medium Risk
1 hour ago
devalue: Residual sparse-array CPU amplification in uneval
1.0.0 - 5.9.2 GHSA-hx4r-w6wj-j8fg
1.0.0 - 5.9.2 GHSA-hx4r-w6wj-j8fg
High Risk
1 hour ago
devalue: Repeated primitive strings cause quadratic expansion in uneval
1.0.0 - 5.9.2 GHSA-mcm9-63f2-9j32
1.0.0 - 5.9.2 GHSA-mcm9-63f2-9j32
Low Risk
1 hour ago
devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
1.0.0 - 5.9.2 GHSA-wf3x-273g-mvxv
1.0.0 - 5.9.2 GHSA-wf3x-273g-mvxv
High Risk
2 hours ago
devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
5.8.0 - 5.9.2 GHSA-x5rw-q4pp-hg5g
5.8.0 - 5.9.2 GHSA-x5rw-q4pp-hg5g
Impacted packages
Timeline
Published
2 hours ago
October 01, 2026 at 03:15 PM UTC
Fixed (5.9.3)
Unknown
Unknown
Last Modified
1 hour ago
October 01, 2026 at 03:30 PM UTC