Tag
#devalue
blogHIGH 8.2
Understanding the devalue stringifyAsync Unhandled Rejection Vulnerability
The devalue library's stringifyAsync function can cause an unhandled rejection despite a caught returned promise, potentially leading to process termination under Node's default unhandled-rejection behavior. This vulnerability has a CVSS score of 8.2 and is classified under CWE-248 and CWE-755. Although it's highly unlikely to be exploited, applications with asynchronous failures influenced by requests are potentially exposed.
newsHIGH 8.2
devalue Vulnerability: Quadratic Expansion in uneval
A vulnerability in the devalue library, specifically in the uneval function, can cause quadratic expansion when handling repeated primitive strings, leading to potential performance issues and amplification attacks. This affects devalue versions <= 5.9.2. Update to version 5.9.3 or later to mitigate.