lowVulnerability
GHSA-wf3x-273g-mvxv
Evaluating legitimate `uneval` output for a sparse array can allocate memory proportional to its declared length. A tiny serialized value can therefore cause large memory allocation in a consuming browser/runtime. This occurs during evaluation of generated code, not in default `parse` sparse-array construction. You would only be affected by this if you were serializing very large sparse arrays and then evaluating the results. In the general use case for `uneval` of sending data to the client, the worst that could happen is the browser tab running out of memory.
Properties
- ghsa_id
- GHSA-wf3x-273g-mvxv
- summary
- devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
- severity
- low
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-wf3x-273g-mvxv
- signal_observed_at
- 2026-10-01T19:14:01+00:00
- is_ghsa_only
- true
- retrieved_at
- 2026-10-01T19:14:01+00:00
- ghsa_published
- 2026-10-01T15:17:13Z
- source_url
- https://github.com/advisories/GHSA-wf3x-273g-mvxv
- ghsa_updated
- 2026-10-01T15:17:16Z
Related Entities (5)
HAS_WEAKNESS (2)
→[Weakness]Memory Allocation with Excessive Size Value
→[Weakness]Uncontrolled Resource Consumption
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]npm/devalue
AFFECTS (1)
→[Software]npm/devalue
Explore deeper with Ninja Signal's threat intelligence graph