[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#CWE-248

blogHIGH 8.2

Understanding the devalue stringifyAsync Unhandled Rejection Vulnerability

The devalue library's stringifyAsync function can cause an unhandled rejection despite a caught returned promise, potentially leading to process termination under Node's default unhandled-rejection behavior. This vulnerability has a CVSS score of 8.2 and is classified under CWE-248 and CWE-755. Although it's highly unlikely to be exploited, applications with asynchronous failures influenced by requests are potentially exposed.

Oct 2, 20261 source