---
id: GHSA-x5rw-q4pp-hg5g
title: >-
  devalue: stringifyAsync can cause an unhandled rejection despite a caught
  returned promise
summary: >-
  devalue: stringifyAsync can cause an unhandled rejection despite a caught
  returned promise
severity: high
cwe:
  - CWE-248
  - CWE-755
vendor: devalue
product: devalue
ecosystem: npm
affected:
  - 'devalue >= 5.8.0, <= 5.9.2'
patched:
  - devalue 5.9.3
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:15:15Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-x5rw-q4pp-hg5g'
references:
  - url: >-
      https://github.com/sveltejs/devalue/security/advisories/GHSA-x5rw-q4pp-hg5g
  - url: >-
      https://github.com/sveltejs/devalue/commit/dae8153e9d7541b975cc4018138d6cebec6c1199
  - url: 'https://github.com/sveltejs/devalue/releases/tag/v5.9.3'
  - url: 'https://github.com/advisories/GHSA-x5rw-q4pp-hg5g'
tags:
  - ghsa
  - npm
ingestedAt: '2026-10-01T15:48:17.831Z'
---

## Overview

When serializing multiple promises, a later promise can reject before an earlier one settles. An internal rejected promise remains unhandled even if the caller catches the returned `stringifyAsync` promise. Under Node's default unhandled-rejection behavior this can terminate the process. Applications whose asynchronous failures/timing can be influenced by requests are potentially exposed.

This is essentially impossible to exploit, and is much more likely to surface as a developer-introduced bug.

## Affected packages

- `devalue >= 5.8.0, <= 5.9.2`

## Remediation

Upgrade to a patched release:

- `devalue 5.9.3`
