CVE-2026-22774High· 7.5▾ TwilightSvelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potenti…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
0.6% → 0.6%
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input from untrusted sources. This affects applications using devalue.parse on externally-supplied data. The root cause is the typed array hydration expecting an ArrayBuffer as input, but not checking the assumption before creating the typed array. This vulnerability is fixed in 5.6.2.
devalue >= 5.3.0, < 5.6.2Upgrade past the affected range:
devalue 5.6.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-22775High· 7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job
CVE-2026-92708High· 7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job
CVE-2026-81176Medium· 5.3Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job
CVE-2026-75029Medium· 5.3In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record)
CVE-2026-68531Low· 2.1Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and page list, allowing an authenticated user with editor-level or higher privileges to submit …
CVE-2026-87011High· 7.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform