GHSA-j22f-vq7h-c4qm

Suggest an improvement
Source
https://github.com/advisories/GHSA-j22f-vq7h-c4qm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-j22f-vq7h-c4qm/GHSA-j22f-vq7h-c4qm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j22f-vq7h-c4qm
Aliases
Published
2026-10-01T15:18:06Z
Modified
2026-10-01T15:30:12Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
devalue: `stringify`/`uneval` serialize shared memory
Details

Impact

stringify and uneval serialize a typed array by emitting its backing ArrayBuffer, not just the view. In the case of a Node Buffer object, the backing buffer is a process-wide shared pool, meaning unrelated memory can be serialized into a response that is then sent to the client. For a Node Buffer the backing store is Node's process-wide shared pool, so serializing a small Buffer copies up to 64 KB of unrelated process memory — including bytes from other in-flight requests — into the output. In an SSR framework (SvelteKit, Nuxt) a public page whose load() returns a 2-byte Buffer, or a small file read with readFileSync, ships another user's request body / Authorization header in its HTML. Unauthenticated, silent, ~43,000× amplification.

This is serialization-side, so the parse/unflatten prototype-pollution and DoS guards do not apply — it fires on every SSR render, not only when parsing untrusted input.

Workarounds

Convert Node Buffer objects to Uint8Array:

payload = {
- buffer
+ buffer: new Uint8Array(buffer)
}
Database specific
{
    "cwe_ids":  [
        "CWE-200",
        "CWE-226"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-01T15:18:06Z",
    "nvd_published_at":  "2026-09-18T20:17:30Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / devalue

Package

Affected ranges

Type
SEMVER
Events
Introduced
5.1.0
Fixed
5.9.3

Database specific

last_known_affected_version_range
"<= 5.9.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-j22f-vq7h-c4qm/GHSA-j22f-vq7h-c4qm.json"