Intel

AIKIDO-2026-674264

devalue is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-r9w8-h9r3-54w4 Published Yesterday

37

Low Risk

This Affects:

JSdevalue
0.0.1 - 5.9.2
Fixed in 5.9.3
Are you affected? Scan for Free

TL;DR

parse and unflatten pass a revived backing buffer into a typed-array or DataView constructor without checking its type. A custom ArrayBuffer reviver that returns a number or an array-like value makes the constructor allocate a new buffer from that length, so a small payload can request a huge allocation. The fix reads byteLength through the native getter and rejects anything that is not a real ArrayBuffer or SharedArrayBuffer before construction.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you supply a custom ArrayBuffer reviver to parse or unflatten.

Background info

devalue is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 5.9.2.

How to fix this

Upgrade the devalue library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform