Security Advisories for devalue in npm
Low
3 months ago
Sveltejs devalue's `devalue.parse` and `devalue.unflatten` emit objects with `__proto__` own properties
npm
devalue
Moderate
3 months ago
devalue has prototype pollution in devalue.parse and devalue.unflatten
npm
devalue
Low
3 months ago
devalue `uneval`ed code can create objects with polluted prototypes when `eval`ed
npm
devalue
High
5 months ago
devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse
npm
devalue
High
5 months ago
Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parse
npm
devalue