GHSA-hx4r-w6wj-j8fgMediumDisclosed before NVD
devalue: Residual sparse-array CPU amplification in uneval
📋 Description
uneval performs synchronous work proportional to a sparse array's declared length. An application that passes attacker-influenced sparse values to uneval can suffer event-loop blocking. Since attacker-controlled creation of sparse arrays is so difficult, this vulnerability is very difficult to exploit.
🎯 Affected products1
- npm/devalue:<= 5.9.2