In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.
Start learningUpgrade devalue to version 5.6.3 or higher.
devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the uneval() or stringify() functions. An attacker can cause CPU and memory exhaustion by submitting specially crafted sparse arrays.