<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:devalue_project:devalue:*:*:*:*:*:node.js:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3adevalue_projectdevaluenode.js/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 20:22:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3adevalue_projectdevaluenode.js/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Information Disclosure via Improper Buffer Serialization in devalue</title><link>https://feed.craftedsignal.io/briefs/2026-10-devalue-memory-leak/</link><pubDate>Thu, 01 Oct 2026 20:22:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-devalue-memory-leak/</guid><description>The devalue library improperly serializes Node.js Buffer objects, exposing up to 64 KB of process-wide memory to end users in SSR environments via CVE-2026-92708.</description><content:encoded><![CDATA[<p>The 'devalue' npm package (versions 5.1.0 through 5.9.2) contains an information disclosure vulnerability, identified as CVE-2026-92708, resulting from incorrect serialization of Node.js Buffer objects. When using the 'stringify' or 'uneval' functions, the library serializes the underlying process-wide memory backing the Buffer rather than the specific view intended.</p>
<p>Because Node.js utilizes a shared pool for Buffer memory, this vulnerability allows for the leakage of up to 64 KB of unrelated process memory into serialized output. In the context of Server-Side Rendering (SSR) frameworks such as SvelteKit or Nuxt, this behavior can be exploited by an unauthenticated party to extract sensitive data belonging to other users. This includes bytes from concurrent requests, such as HTTP request bodies or Authorization headers, which are subsequently embedded into server-rendered HTML. Unlike other vulnerabilities in the library, this issue occurs during serialization and is not mitigated by existing prototype pollution or Denial of Service guards, potentially impacting every SSR render involving Buffer objects.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a severe risk of data exfiltration in web applications utilizing 'devalue' for server-side state serialization. By repeatedly triggering server-side renders that include small Buffers, an attacker can harvest sensitive data from the application's process memory. This exposure includes authentication tokens, user-specific request data, and other sensitive information from concurrent traffic. Successful exploitation leads to unauthorized data access and potential account takeover or business logic compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize remediation for all applications using 'devalue' for SSR state handling.</p>
<ul>
<li>Upgrade to a version of 'devalue' that addresses the memory serialization behavior.</li>
<li>If an immediate upgrade is unavailable, manually convert all Node.js Buffer objects to Uint8Array instances before passing them to 'devalue.stringify()' or 'devalue.uneval()' as a temporary mitigation.</li>
<li>Audit SSR logic in SvelteKit and Nuxt applications to identify instances where Buffer objects are included in serialized state.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>information-disclosure</category><category>supply-chain</category><category>npm</category><category>ssr</category></item></channel></rss>