MajorCritical vulnerability
devalue: Repeated primitive strings cause quadratic expansion in uneval
GitHub Advisories · officialPublished Oct 1, 2026Risk 37/100
Under very constrained circumstances, data that was `parse`d and then passed to `uneval` could turn a small payload into a very large serialized string.
Recommended action
Recommended action
Upgrade affected packages to a patched version: devalue 5.9.3.
Technical details
- Vendor
- Not specified
- Product
- devalue
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source