---
id: GHSA-hx4r-w6wj-j8fg
title: 'devalue: Residual sparse-array CPU amplification in uneval'
summary: 'devalue: Residual sparse-array CPU amplification in uneval'
severity: medium
cwe:
  - CWE-400
  - CWE-407
vendor: devalue
product: devalue
ecosystem: npm
affected:
  - devalue <= 5.9.2
patched:
  - devalue 5.9.3
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:17:43Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-hx4r-w6wj-j8fg'
references:
  - url: >-
      https://github.com/sveltejs/devalue/security/advisories/GHSA-hx4r-w6wj-j8fg
  - url: >-
      https://github.com/sveltejs/devalue/commit/6861dbbb7e548849e48bce718e88747a298f7250
  - url: 'https://github.com/sveltejs/devalue/releases/tag/v5.9.3'
  - url: 'https://github.com/advisories/GHSA-hx4r-w6wj-j8fg'
tags:
  - ghsa
  - npm
ingestedAt: '2026-10-01T15:48:17.830Z'
---

## Overview

`uneval` performs synchronous work proportional to a sparse array's declared length. An application that passes attacker-influenced sparse values to `uneval` can suffer event-loop blocking. Since attacker-controlled creation of sparse arrays is so difficult, this vulnerability is very difficult to exploit.

## Affected packages

- `devalue <= 5.9.2`

## Remediation

Upgrade to a patched release:

- `devalue 5.9.3`
