highVulnerability

GHSA-x5rw-q4pp-hg5g

When serializing multiple promises, a later promise can reject before an earlier one settles. An internal rejected promise remains unhandled even if the caller catches the returned `stringifyAsync` promise. Under Node's default unhandled-rejection behavior this can terminate the process. Applications whose asynchronous failures/timing can be influenced by requests are potentially exposed. This is essentially impossible to exploit, and is much more likely to surface as a developer-introduced bug.

Properties

ghsa_id
GHSA-x5rw-q4pp-hg5g
summary
devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
severity
high
last_source
GitHub Advisory Database
cve_id
GHSA-x5rw-q4pp-hg5g
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
true
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T15:15:13Z
source_url
https://github.com/advisories/GHSA-x5rw-q4pp-hg5g
ghsa_updated
2026-10-01T15:15:15Z

Related Entities (5)

HAS_WEAKNESS (2)

→[Weakness]Uncaught Exception
→[Weakness]Improper Handling of Exceptional Conditions

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/devalue

AFFECTS (1)

→[Software]npm/devalue

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-x5rw-q4pp-hg5g — Ninja Signal Threat Intelligence | Ninja Signal