Junglewise Threat Intelligence

devalue unhandled promise rejection in stringifyAsync

Severity: high · Published 2026-10-01

Technologies: devalue (npm). Vendors: npm.

Executive brief

devalue is a JavaScript serialization library used to convert data structures to strings. When serializing multiple promises, an internal promise rejection can remain unhandled even if the application catches the main returned promise, causing Node.js to terminate the process under default behavior. Exploitation is extremely unlikely and the issue is typically introduced by developer timing or error handling patterns rather than malicious input.

Affected products

  • npm devalue

Related threats