Prototype pollution in devalue - CVE-2026-30226
Published: April 24, 2026
devalue
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improperly controlled modification of object prototype attributes in devalue.parse and devalue.unflatten when parsing maliciously crafted payloads. A remote attacker can supply a specially crafted payload to cause a denial of service.
The issue may also lead to type confusion.