lowVulnerability

GHSA-wf3x-273g-mvxv

Evaluating legitimate `uneval` output for a sparse array can allocate memory proportional to its declared length. A tiny serialized value can therefore cause large memory allocation in a consuming browser/runtime. This occurs during evaluation of generated code, not in default `parse` sparse-array construction. You would only be affected by this if you were serializing very large sparse arrays and then evaluating the results. In the general use case for `uneval` of sending data to the client, the worst that could happen is the browser tab running out of memory.

Properties

ghsa_id
GHSA-wf3x-273g-mvxv
summary
devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
severity
low
last_source
GitHub Advisory Database
cve_id
GHSA-wf3x-273g-mvxv
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
true
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T15:17:13Z
source_url
https://github.com/advisories/GHSA-wf3x-273g-mvxv
ghsa_updated
2026-10-01T15:17:16Z

Related Entities (5)

HAS_WEAKNESS (2)

→[Weakness]Memory Allocation with Excessive Size Value
→[Weakness]Uncontrolled Resource Consumption

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/devalue

AFFECTS (1)

→[Software]npm/devalue

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-wf3x-273g-mvxv — Ninja Signal Threat Intelligence | Ninja Signal