{"id":"GHSA-x5rw-q4pp-hg5g","title":"devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise","summary":"devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise","severity":"high","cwe":["CWE-248","CWE-755"],"vendor":"devalue","product":"devalue","ecosystem":"npm","affected":["devalue >= 5.8.0, <= 5.9.2"],"patched":["devalue 5.9.3"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:15:15Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-x5rw-q4pp-hg5g","references":[{"url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-x5rw-q4pp-hg5g"},{"url":"https://github.com/sveltejs/devalue/commit/dae8153e9d7541b975cc4018138d6cebec6c1199"},{"url":"https://github.com/sveltejs/devalue/releases/tag/v5.9.3"},{"url":"https://github.com/advisories/GHSA-x5rw-q4pp-hg5g"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-01T15:48:17.831Z","slug":"GHSA-x5rw-q4pp-hg5g","body":"## Overview\n\nWhen serializing multiple promises, a later promise can reject before an earlier one settles. An internal rejected promise remains unhandled even if the caller catches the returned `stringifyAsync` promise. Under Node's default unhandled-rejection behavior this can terminate the process. Applications whose asynchronous failures/timing can be influenced by requests are potentially exposed.\n\nThis is essentially impossible to exploit, and is much more likely to surface as a developer-introduced bug.\n\n## Affected packages\n\n- `devalue >= 5.8.0, <= 5.9.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `devalue 5.9.3`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}