{"id":"GHSA-j22f-vq7h-c4qm","summary":"devalue: `stringify`/`uneval` serialize shared memory","details":"### Impact\n\n`stringify` and `uneval` serialize a typed array by emitting its backing `ArrayBuffer`, not just the view. In the case of a Node `Buffer` object, the backing buffer is a process-wide shared pool, meaning unrelated memory can be serialized into a response that is then sent to the client. For a Node `Buffer` the backing store is Node's **process-wide shared pool**, so serializing a small `Buffer` copies up to 64 KB of unrelated process memory — including bytes from other in-flight requests — into the output. In an SSR framework (SvelteKit, Nuxt) a public page whose `load()` returns a 2-byte `Buffer`, or a small file read with `readFileSync`, ships another user's request body / `Authorization` header in its HTML. Unauthenticated, silent, ~43,000× amplification.\n\nThis is serialization-side, so the `parse`/`unflatten` prototype-pollution and DoS guards do not apply — it fires on every SSR render, not only when parsing untrusted input.\n\n### Workarounds\n\nConvert Node `Buffer` objects to `Uint8Array`:\n\n```diff\npayload = {\n- buffer\n+ buffer: new Uint8Array(buffer)\n}\n```","aliases":["CVE-2026-92708"],"modified":"2026-10-01T15:30:12.678757365Z","published":"2026-10-01T15:18:06Z","database_specific":{"cwe_ids":["CWE-200","CWE-226"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-01T15:18:06Z","nvd_published_at":"2026-09-18T20:17:30Z"},"references":[{"type":"WEB","url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-j22f-vq7h-c4qm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92708"},{"type":"WEB","url":"https://github.com/sveltejs/devalue/commit/46dc877b3570dafb1cd3291b9bb48cecef8f7266"},{"type":"PACKAGE","url":"https://github.com/sveltejs/devalue"},{"type":"WEB","url":"https://github.com/sveltejs/devalue/releases/tag/v5.9.3"}],"affected":[{"package":{"name":"devalue","ecosystem":"npm","purl":"pkg:npm/devalue"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.1.0"},{"fixed":"5.9.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 5.9.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-j22f-vq7h-c4qm/GHSA-j22f-vq7h-c4qm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}