Junglewise Threat Intelligence

devalue stringifyAsync unhandled promise rejection

Severity: medium · CVSS 4 · Published 2026-10-01

Technologies: devalue (npm), Svelte Devalue. Vendors: npm, Svelte.

Executive brief

The devalue library, which serializes JavaScript values for transfer between server and client in web applications, can fail to handle promise rejections properly when serializing multiple promises. If a later promise rejects before an earlier one settles, an unhandled rejection remains even if the caller catches the returned promise, potentially causing the entire Node.js process to terminate under default error handling behavior.

Technical details

The vulnerability is an unhandled promise rejection in stringifyAsync (CWE-248, CWE-755) when serializing multiple concurrent promises. If an internal promise rejects before the outer stringifyAsync promise can establish proper error handling, the rejection propagates uncaught. An attacker cannot directly exploit this; it surfaces primarily as a developer-introduced bug when application timing/failure modes are influenced by external requests.

Affected products

  • Svelte devalue 5.8.0 through 5.9.2

Timeline

  • 2026-10-01: disclosed: GHSA-x5rw-q4pp-hg5g published
  • 2026-09-18: patched: Fix merged in commit dae8153e9d7541b975cc4018138d6cebec6c1199
  • 2026-09-18: advisory: Security advisory filed by elliott-with-the-longest-name-on-github

References

Related threats