Inefficient Algorithmic Complexity in devalue - #VU151499
Published: September 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause event-loop blocking.
The vulnerability exists due to inefficient algorithmic complexity in the uneval function when processing attacker-influenced sparse arrays. A remote attacker can supply a sparse array with a large declared length to cause event-loop blocking.
Exploitation is very difficult because attacker-controlled creation of sparse arrays is difficult.