Improper handling of highly compressed data in devalue - #VU151498
Published: September 21, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of data amplification in the uneval function when serializing data previously processed by parse. A local user can provide data containing repeated primitive strings to cause a denial of service.
Exploitation is possible only under very constrained circumstances.