{"id":"GHSA-hx4r-w6wj-j8fg","title":"devalue: Residual sparse-array CPU amplification in uneval","summary":"devalue: Residual sparse-array CPU amplification in uneval","severity":"medium","cwe":["CWE-400","CWE-407"],"vendor":"devalue","product":"devalue","ecosystem":"npm","affected":["devalue <= 5.9.2"],"patched":["devalue 5.9.3"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:17:43Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-hx4r-w6wj-j8fg","references":[{"url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-hx4r-w6wj-j8fg"},{"url":"https://github.com/sveltejs/devalue/commit/6861dbbb7e548849e48bce718e88747a298f7250"},{"url":"https://github.com/sveltejs/devalue/releases/tag/v5.9.3"},{"url":"https://github.com/advisories/GHSA-hx4r-w6wj-j8fg"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-01T15:48:17.830Z","slug":"GHSA-hx4r-w6wj-j8fg","body":"## Overview\n\n`uneval` performs synchronous work proportional to a sparse array's declared length. An application that passes attacker-influenced sparse values to `uneval` can suffer event-loop blocking. Since attacker-controlled creation of sparse arrays is so difficult, this vulnerability is very difficult to exploit.\n\n## Affected packages\n\n- `devalue <= 5.9.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `devalue 5.9.3`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}