Uncontrolled Memory Allocation in devalue - #VU151496
Published: September 21, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper validation of typed-array allocations in the parse function's custom ArrayBuffer reviver handling when processing input with a malformed ArrayBuffer custom reviver. A local user can provide a small input that causes a massive ArrayBuffer allocation to cause a denial of service.