GHSA-x5rw-q4pp-hg5gHigh▾ Twilightdevalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
When serializing multiple promises, a later promise can reject before an earlier one settles. An internal rejected promise remains unhandled even if the caller catches the returned stringifyAsync promise. Under Node's default unhandled-rejection behavior this can terminate the process. Applications whose asynchronous failures/timing can be influenced by requests are potentially exposed.
This is essentially impossible to exploit, and is much more likely to surface as a developer-introduced bug.
devalue >= 5.8.0, <= 5.9.2Upgrade to a patched release:
devalue 5.9.3Connected by shared product, vendor, weakness, or advisory.
GHSA-4q55-j62x-fr9hMediumdevalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion
GHSA-hx4r-w6wj-j8fgMediumdevalue: Residual sparse-array CPU amplification in uneval
GHSA-mcm9-63f2-9j32Highdevalue: Repeated primitive strings cause quadratic expansion in uneval
GHSA-wf3x-273g-mvxvLowdevalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
CVE-2026-92708High· 7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job
CVE-2026-81176Medium· 5.3Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job