GHSA-x5rw-q4pp-hg5gHighDisclosed before NVD

devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise

Published
October 1, 2026
Last Modified
October 1, 2026

📋 Description

When serializing multiple promises, a later promise can reject before an earlier one settles. An internal rejected promise remains unhandled even if the caller catches the returned stringifyAsync promise. Under Node's default unhandled-rejection behavior this can terminate the process. Applications whose asynchronous failures/timing can be influenced by requests are potentially exposed.

This is essentially impossible to exploit, and is much more likely to surface as a developer-introduced bug.

🎯 Affected products1

  • npm/devalue:>= 5.8.0, <= 5.9.2

🔗 References (4)