Vulnerability GHSA-x5rw-q4pp-hg5g

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 01, 2026 at 03:15 PM UTC
devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
5.8.0 - 5.9.2
5.8.0 - 5.9.2

Summary

devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise

Details

When serializing multiple promises, a later promise can reject before an earlier one settles. An internal rejected promise remains unhandled even if the caller catches the returned stringifyAsync promise. Under Node's default unhandled-rejection behavior this can terminate the process. Applications whose asynchronous failures/timing can be influenced by requests are potentially exposed.

This is essentially impossible to exploit, and is much more likely to surface as a developer-introduced bug.

Impacted packages

Timeline

Published
2 hours ago
October 01, 2026 at 03:15 PM UTC
Fixed (5.9.3)
Unknown
Unknown
Last Modified
1 hour ago
October 01, 2026 at 03:30 PM UTC