Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade devalue to version 5.9.3 or higher.
devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.
Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity via the uneval function in src/uneval.js when processing a sparse array with a very large index (e.g., arr[1000000] = 1). The function previously used forEach to iterate over the logical length of dictionary-backed sparse arrays, causing it to allocate and scan every slot up to the array's length rather than only the populated indices. An attacker who can supply a sparse array value to uneval can trigger excessive memory allocation and CPU consumption, crashing the process.