GHSA-hx4r-w6wj-j8fgMedium▾ Sunlitdevalue: Residual sparse-array CPU amplification in uneval
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
uneval performs synchronous work proportional to a sparse array's declared length. An application that passes attacker-influenced sparse values to uneval can suffer event-loop blocking. Since attacker-controlled creation of sparse arrays is so difficult, this vulnerability is very difficult to exploit.
devalue <= 5.9.2Upgrade to a patched release:
devalue 5.9.3Connected by shared product, vendor, weakness, or advisory.
GHSA-wf3x-273g-mvxvLowdevalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
GHSA-mcm9-63f2-9j32Highdevalue: Repeated primitive strings cause quadratic expansion in uneval
GHSA-x5rw-q4pp-hg5gHighdevalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
GHSA-4q55-j62x-fr9hMediumdevalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion
CVE-2026-92708High· 7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job
CVE-2026-102277Medium· 5.3The brace-expansion library generates arbitrary strings containing a common prefix and suffix