Sensitive Information in Resource Not Removed Before Reuse in devalue - CVE-2026-92708
Published: September 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to sensitive information in a resource not removed before reuse in the `stringify` and `uneval` serialization functions when serializing Node `Buffer` objects. A remote attacker can request a server-side rendered page that serializes a Node `Buffer` to disclose sensitive information.
The Node `Buffer` backing store is a process-wide shared pool, and serialization can include unrelated memory from other in-flight requests in the response.