Vulnerabilities
Last updated 35 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
devalue: Custom ArrayBuffer revivers can bypass typed-array allocation validation | High Risk 8.0 | 3 hours ago | 3 hours ago |
|
|
devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated | Low Risk 3.0 | 3 hours ago | 3 hours ago |
|
|
devalue: Residual sparse-array CPU amplification in uneval | Medium Risk 6.0 | 3 hours ago | 3 hours ago |
|
|
devalue: `stringify`/`uneval` serialize shared memory | High Risk 7.5 | 3 hours ago | 3 hours ago |
|
|
devalue: Repeated primitive strings cause quadratic expansion in uneval | High Risk 8.0 | 3 hours ago | 3 hours ago |
|
|
devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise | High Risk 8.0 | 3 hours ago | 3 hours ago |
|
|
devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion | Medium Risk 6.0 | 3 hours ago | 3 hours ago |
|
|
Svelte devalue: DoS via malformed input | Medium Risk 5.3 | 13 days ago | 13 days ago |
|
|
Sveltejs devalue's `devalue.parse` and `devalue.unflatten` emit objects with `__proto__` own properties | Low Risk 3.0 | 6 months ago | 3 months ago |
|
|
Svelte devalue: DoS via sparse array deserialization | High Risk 7.5 | 4 months ago | 3 months ago |
|
|
devalue has prototype pollution in devalue.parse and devalue.unflatten | Medium Risk 6.0 | 6 months ago | 6 months ago |
|
|
devalue `uneval`ed code can create objects with polluted prototypes when `eval`ed | Low Risk 3.0 | 7 months ago | 7 months ago |
|
|
devalue affected by CPU and memory amplification from sparse arrays | Low Risk 3.0 | 7 months ago | 7 months ago |
|
|
devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse | High Risk 7.5 | 8 months ago | 8 months ago |
|
|
Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parse | High Risk 7.5 | 8 months ago | 8 months ago |
|
|
devalue prototype pollution vulnerability | High Risk 8.0 | 1 year ago | 1 year ago |
|
|
Malicious code in becoming-the-narcissists-nightmare-how-to-devalue-and-discard-the-narcissist-while-supplying-yoursel (npm) | Unknown | 3 years ago | 2 years ago |
|
|
Malicious code in dow-load-becoming-the-narcissists-nightmare-how-to-devalue-and-discard-the-narcissist-whil (npm) | Unknown | 3 years ago | 2 years ago |
|
|
Cross-Site Scripting in @nuxt/devalue | Medium Risk 6.1 | 7 years ago | 2 years ago |
Page 1