Uncontrolled Memory Allocation in devalue - #VU151497
Published: September 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to memory allocation with excessive size value in uneval-generated sparse-array code when evaluating generated code for sparse arrays. A remote attacker can trigger evaluation of generated sparse-array code to cause a denial of service.
Default parse sparse-array construction is not affected.