GHSA-hx4r-w6wj-j8fg: Npm/devalue vulnerability
uneval performs synchronous work proportional to a sparse array's declared length. An application that passes attacker-influenced sparse values to uneval can suffer event-loop blocking. Since attacker-controlled creation of sparse arrays is so difficult, this vulnerability is very difficult to exploit.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/devalueto a version that resolves this vulnerability.Fixed in 5.9.3
Event History
Frequently Asked Questions
Which applications are realistically exposed to event-loop blocking?
Applications are exposed only if they pass attacker-influenced sparse array values to uneval. The advisory notes that attacker-controlled creation of sparse arrays is very difficult, making exploitation difficult in practice.
What capability does an attacker need to exploit this issue?
An attacker needs to cause the application to provide a sparse array with a large declared length to uneval. Processing is synchronous and proportional to that declared length, so successful exploitation can block the event loop.