devalue@5.1.0

Gets the job done when JSON.stringify can't

  • latest version

    6.0.2

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    19 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the devalue package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Prototype Pollution

    devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.

    Affected versions of this package are vulnerable to Prototype Pollution via the unflatten function in src/parse.js, where object keys parsed from untrusted input are not validated to be strings before being set on the target object. An attacker who controls the serialized input can supply a non-string key (such as a numeric or symbol-like value) that bypasses the existing __proto__ guard, potentially polluting the prototype chain of the resulting object and influencing downstream application behavior.

    How to fix Prototype Pollution?

    Upgrade devalue to version 5.9.3 or higher.

    <5.9.3
    • L
    Memory Allocation with Excessive Size Value

    devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.

    Affected versions of this package are vulnerable to Memory Allocation with Excessive Size Value via the uneval function in src/uneval.js when processing a sparse array with a very large index (e.g., arr[1000000] = 1). The function previously used Array.prototype.forEach, which iterates over every logical slot up to the array's length, causing excessive CPU and memory consumption proportional to the declared array length rather than the number of populated elements. An attacker who can supply a serializable value containing a sparse array can trigger this condition to exhaust server resources.

    How to fix Memory Allocation with Excessive Size Value?

    Upgrade devalue to version 5.9.3 or higher.

    >=1.0.0 <5.9.3
    • H
    Improper Handling of Highly Compressed Data (Data Amplification)

    devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.

    Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) via the uneval function when serializing a value containing many repeated long strings or bigint primitives. Each repeated primitive is re-stringified on every reference rather than being deduplicated, causing the output size to grow quadratically with the number of repetitions. An attacker who can supply input to a uneval call can trigger excessive CPU and memory consumption, crashing the process.

    How to fix Improper Handling of Highly Compressed Data (Data Amplification)?

    Upgrade devalue to version 5.9.3 or higher.

    <5.9.3
    • M
    Inefficient Algorithmic Complexity

    devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.

    Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity via the uneval function in src/uneval.js when processing a sparse array with a very large index (e.g., arr[1000000] = 1). The function previously used forEach to iterate over the logical length of dictionary-backed sparse arrays, causing it to allocate and scan every slot up to the array's length rather than only the populated indices. An attacker who can supply a sparse array value to uneval can trigger excessive memory allocation and CPU consumption, crashing the process.

    How to fix Inefficient Algorithmic Complexity?

    Upgrade devalue to version 5.9.3 or higher.

    <5.9.3
    • H
    Sensitive Information in Resource Not Removed Before Reuse

    devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.

    Affected versions of this package are vulnerable to Sensitive Information in Resource Not Removed Before Reuse via the viewInfo operation in src/operations.js and the typed-array serialization path in src/uneval.js, when a Node.js Buffer is serialized. Node Buffer instances are backed by a shared memory pool that may contain unrelated, sensitive data beyond the visible bytes of the buffer. Because the library previously serialized the full backing ArrayBuffer rather than only the bytes visible through the Buffer view, an attacker who can influence what gets serialized (for example, during SSR rendering) can cause the full pool contents - including data from other allocations - to be included in the serialized output and exposed to the client.

    How to fix Sensitive Information in Resource Not Removed Before Reuse?

    Upgrade devalue to version 5.9.3 or higher.

    >=5.1.0 <5.9.3
    • M
    Allocation of Resources Without Limits or Throttling

    devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.

    Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the parse function. An attacker can cause excessive resource consumption by submitting specially crafted input that triggers repeated alternation between array representations, leading to significant performance degradation.

    How to fix Allocation of Resources Without Limits or Throttling?

    Upgrade devalue to version 5.9.2 or higher.

    <5.9.2
    • M
    Improper Validation of Specified Type of Input

    devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.

    Affected versions of this package are vulnerable to Improper Validation of Specified Type of Input in the hydrate() function that can accept __proto__ keys emitted from devalue.parse() or devalue.unflatten() functions. An attacker can manipulate object properties by supplying input that creates objects with a __proto__ own property, which may lead to prototype pollution in downstream code when such objects are merged or assigned.

    How to fix Improper Validation of Specified Type of Input?

    Upgrade devalue to version 5.6.4 or higher.

    <5.6.4
    • M
    Prototype Pollution

    devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.

    Affected versions of this package are vulnerable to Prototype Pollution via the parse or unflatten functions. An attacker can manipulate object prototypes by supplying malicious payloads, potentially causing denial of service or type confusion.

    How to fix Prototype Pollution?

    Upgrade devalue to version 5.6.4 or higher.

    >=4.0.0 <5.6.4
    • L
    Prototype Pollution

    devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.

    Affected versions of this package are vulnerable to Prototype Pollution via the uneval method. An attacker can manipulate object prototypes by supplying specially crafted untrusted data that, when processed and later evaluated, results in objects with altered prototypes.

    How to fix Prototype Pollution?

    Upgrade devalue to version 5.6.3 or higher.

    <5.6.3
    • M
    Allocation of Resources Without Limits or Throttling

    devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.

    Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the uneval() or stringify() functions. An attacker can cause CPU and memory exhaustion by submitting specially crafted sparse arrays.

    How to fix Allocation of Resources Without Limits or Throttling?

    Upgrade devalue to version 5.6.3 or higher.

    <5.6.3
    • H
    Asymmetric Resource Consumption (Amplification)

    devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.

    Affected versions of this package are vulnerable to Asymmetric Resource Consumption (Amplification) due to the improper validation in ArrayBuffer if input string is base64 encoded in the hydration() function when parsing data from untrusted sources. An attacker can cause excessive memory allocation and CPU usage by submitting specially crafted input, potentially leading to resource exhaustion and service disruption.

    How to fix Asymmetric Resource Consumption (Amplification)?

    Upgrade devalue to version 5.6.2 or higher.

    >=5.1.0 <5.6.2
    • C
    Prototype Pollution

    devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.

    Affected versions of this package are vulnerable to Prototype Pollution via the parse function. An attacker can manipulate object prototypes or assign array prototype methods to object properties by crafting malicious payloads, potentially leading to property overwrites or bypassing server-side validation.

    How to fix Prototype Pollution?

    Upgrade devalue to version 5.3.2 or higher.

    <5.3.2