{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/devalue--5.9.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["devalue (\u003c= 5.9.2)"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","npm","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Svelte"],"content_html":"\u003cp\u003eThe devalue package for Node.js is susceptible to an uncontrolled resource consumption vulnerability (CWE-400, CWE-409) within its 'uneval' function. When handling specifically crafted data that has been previously parsed, the serialization process can trigger quadratic expansion. This results in a relatively small input payload being transformed into a disproportionately large serialized string. By exploiting this behavior, an attacker can cause the host application to exhaust available system memory and CPU resources, effectively resulting in a denial-of-service condition. This vulnerability affects all versions of devalue up to and including 5.9.2. Developers are urged to update to version 5.9.3 to mitigate this risk, as this patch addresses the logic error leading to the amplification effect.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a web application or internal service that utilizes the 'devalue' library to serialize user-provided data.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious JSON or serialized object payload containing specific, repeated primitive string patterns.\u003c/li\u003e\n\u003cli\u003eThe crafted payload is submitted to the application via an exposed network endpoint.\u003c/li\u003e\n\u003cli\u003eThe application passes the attacker-supplied data into the 'devalue.uneval()' function.\u003c/li\u003e\n\u003cli\u003eThe 'uneval' function fails to constrain the serialization process, resulting in quadratic expansion of the input string.\u003c/li\u003e\n\u003cli\u003eThe application process consumes excessive CPU cycles and memory attempting to allocate the resulting large string.\u003c/li\u003e\n\u003cli\u003eThe system becomes unresponsive or crashes due to resource exhaustion, resulting in a denial-of-service for the service users.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to a denial-of-service for applications relying on the vulnerable library. This can impact any service handling user input, potentially causing service outages that disrupt business operations. The attack is limited to the availability of the vulnerable system, with no documented impact on data confidentiality or integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the 'devalue' package to version 5.9.3 or later in all Node.js projects. Verify project dependencies to identify instances of the vulnerable 'devalue' package (\u0026lt;= 5.9.2). Monitor application logs for high memory usage or frequent service restarts associated with JSON serialization endpoints.\u003c/p\u003e\n","date_modified":"2026-10-01T20:22:32Z","date_published":"2026-10-01T20:22:32Z","id":"https://feed.craftedsignal.io/briefs/2026-10-devalue-quadratic-expansion/","summary":"The devalue package for Node.js is vulnerable to a denial-of-service attack where specially crafted input causes quadratic string expansion during the serialization process, leading to memory and CPU exhaustion.","title":"Uncontrolled Resource Consumption in devalue Serialization","url":"https://feed.craftedsignal.io/briefs/2026-10-devalue-quadratic-expansion/"}],"language":"en","title":"CraftedSignal Threat Feed - Devalue (\u003c= 5.9.2)","version":"https://jsonfeed.org/version/1.1"}