Description
In devalue v5.6.3, devalue.parse and devalue.unflatten were susceptible to prototype pollution via maliciously crafted payloads. Successful exploitation could lead to Denial of Service (DoS) or type confusion.
Recommendation
Update the devalue package to the latest compatible version. Followings are version details:
- Affected version(s): < 5.6.4
- Patched version(s): 5.6.4
References
Could your website be exposed too?
SmartScanner can check your website for devalue has prototype pollution in devalue.parse and devalue.unflatten and gives you actionable findings to investigate.
Start a free scanRelated Issues
- axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions - CVE-2026-44490
- Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix - CVE-2026-44489
- Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection - CVE-2026-33916
- Velocity.js has a Prototype Pollution vulnerability through #set path assignment - CVE-2026-44966


