CVE-2026-92708
### Impact `stringify` and `uneval` serialize a typed array by emitting its backing `ArrayBuffer`, not just the view. In the case of a Node `Buffer` object, the backing buffer is a process-wide shared pool, meaning unrelated memory can be serialized into a response that is then sent to the client. For a Node `Buffer` the backing store is Node's **process-wide shared pool**, so serializing a small `Buffer` copies up to 64 KB of unrelated process memory — including bytes from other in-flight requests — into the output. In an SSR framework (SvelteKit, Nuxt) a public page whose `load()` returns a 2-byte `Buffer`, or a small file read with `readFileSync`, ships another user's request body / `Authorization` header in its HTML. Unauthenticated, silent, ~43,000× amplification. This is serialization-side, so the `parse`/`unflatten` prototype-pollution and DoS guards do not apply — it fires on every SSR render, not only when parsing untrusted input. ### Workarounds Convert Node `Buffer` objects to `Uint8Array`: ```diff payload = { - buffer + buffer: new Uint8Array(buffer) } ```
Properties
- summary
- devalue: `stringify`/`uneval` serialize shared memory
- severity
- high
- cvss_score
- 7.5
- retrieved_at
- 2026-10-01T19:14:01+00:00
- ghsa_published
- 2026-10-01T15:18:06Z
- source_url
- https://github.com/advisories/GHSA-j22f-vq7h-c4qm
- ghsa_updated
- 2026-10-01T15:18:07Z
- ghsa_id
- GHSA-j22f-vq7h-c4qm
- last_source
- GitHub Advisory Database
- cve_id
- CVE-2026-92708
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- signal_observed_at
- 2026-10-01T19:14:01+00:00
- is_ghsa_only
- false
Related Entities (5)
HAS_WEAKNESS (2)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph