{"id":"GHSA-wf3x-273g-mvxv","title":"devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated","summary":"devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated","severity":"low","cwe":["CWE-400","CWE-789"],"vendor":"devalue","product":"devalue","ecosystem":"npm","affected":["devalue >= 1.0.0, <= 5.9.2"],"patched":["devalue 5.9.3"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:17:16Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-wf3x-273g-mvxv","references":[{"url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-wf3x-273g-mvxv"},{"url":"https://github.com/sveltejs/devalue/commit/6861dbbb7e548849e48bce718e88747a298f7250"},{"url":"https://github.com/sveltejs/devalue/releases/tag/v5.9.3"},{"url":"https://github.com/advisories/GHSA-wf3x-273g-mvxv"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-01T15:48:17.830Z","slug":"GHSA-wf3x-273g-mvxv","body":"## Overview\n\nEvaluating legitimate `uneval` output for a sparse array can allocate memory proportional to its declared length. A tiny serialized value can therefore cause large memory allocation in a consuming browser/runtime. This occurs during evaluation of generated code, not in default `parse` sparse-array construction.\n\nYou would only be affected by this if you were serializing very large sparse arrays and then evaluating the results. In the general use case for `uneval` of sending data to the client, the worst that could happen is the browser tab running out of memory.\n\n## Affected packages\n\n- `devalue >= 1.0.0, <= 5.9.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `devalue 5.9.3`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}