Product
The devalue package for Node.js is vulnerable to a denial-of-service attack where specially crafted input causes quadratic string expansion during the serialization process, leading to memory and CPU exhaustion.