GHSA-x5rw-q4pp-hg5g: Npm/devalue vulnerability
When serializing multiple promises, a later promise can reject before an earlier one settles. An internal rejected promise remains unhandled even if the caller catches the returned stringifyAsync promise. Under Node's default unhandled-rejection behavior this can terminate the process. Applications whose asynchronous failures/timing can be influenced by requests are potentially exposed.
This is essentially impossible to exploit, and is much more likely to surface as a developer-introduced bug.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/devalueto a version that resolves this vulnerability.Fixed in 5.9.3
Event History
Frequently Asked Questions
Which applications are most likely to be affected?
Applications are potentially exposed when request handling can influence asynchronous failures or the timing of multiple promises being serialized. The issue is much more likely to appear as a developer-introduced bug than as an exploitable condition.
Can handling errors from the returned stringifyAsync promise prevent process termination?
No. A later internal promise can remain unhandled even when the caller catches the promise returned by stringifyAsync.
What is the likely operational impact under Node's default settings?
Node's default unhandled-rejection behavior can terminate the process when the internal rejected promise is left unhandled.