<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Devalue (&lt;= 5.9.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/devalue--5.9.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 20:22:32 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/devalue--5.9.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Uncontrolled Resource Consumption in devalue Serialization</title><link>https://feed.craftedsignal.io/briefs/2026-10-devalue-quadratic-expansion/</link><pubDate>Thu, 01 Oct 2026 20:22:32 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-devalue-quadratic-expansion/</guid><description>The devalue package for Node.js is vulnerable to a denial-of-service attack where specially crafted input causes quadratic string expansion during the serialization process, leading to memory and CPU exhaustion.</description><content:encoded><![CDATA[<p>The devalue package for Node.js is susceptible to an uncontrolled resource consumption vulnerability (CWE-400, CWE-409) within its 'uneval' function. When handling specifically crafted data that has been previously parsed, the serialization process can trigger quadratic expansion. This results in a relatively small input payload being transformed into a disproportionately large serialized string. By exploiting this behavior, an attacker can cause the host application to exhaust available system memory and CPU resources, effectively resulting in a denial-of-service condition. This vulnerability affects all versions of devalue up to and including 5.9.2. Developers are urged to update to version 5.9.3 to mitigate this risk, as this patch addresses the logic error leading to the amplification effect.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An attacker identifies a web application or internal service that utilizes the 'devalue' library to serialize user-provided data.</li>
<li>The attacker crafts a malicious JSON or serialized object payload containing specific, repeated primitive string patterns.</li>
<li>The crafted payload is submitted to the application via an exposed network endpoint.</li>
<li>The application passes the attacker-supplied data into the 'devalue.uneval()' function.</li>
<li>The 'uneval' function fails to constrain the serialization process, resulting in quadratic expansion of the input string.</li>
<li>The application process consumes excessive CPU cycles and memory attempting to allocate the resulting large string.</li>
<li>The system becomes unresponsive or crashes due to resource exhaustion, resulting in a denial-of-service for the service users.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to a denial-of-service for applications relying on the vulnerable library. This can impact any service handling user input, potentially causing service outages that disrupt business operations. The attack is limited to the availability of the vulnerable system, with no documented impact on data confidentiality or integrity.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the 'devalue' package to version 5.9.3 or later in all Node.js projects. Verify project dependencies to identify instances of the vulnerable 'devalue' package (&lt;= 5.9.2). Monitor application logs for high memory usage or frequent service restarts associated with JSON serialization endpoints.</p>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>denial-of-service</category><category>npm</category><category>supply-chain</category></item></channel></rss>