GHSA-mcm9-63f2-9j32High▾ Twilightdevalue: Repeated primitive strings cause quadratic expansion in uneval
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Under very constrained circumstances, data that was parsed and then passed to uneval could turn a small payload into a very large serialized string.
devalue <= 5.9.2Upgrade to a patched release:
devalue 5.9.3Connected by shared product, vendor, weakness, or advisory.
GHSA-hx4r-w6wj-j8fgMediumdevalue: Residual sparse-array CPU amplification in uneval
GHSA-wf3x-273g-mvxvLowdevalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
GHSA-x5rw-q4pp-hg5gHighdevalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
GHSA-4q55-j62x-fr9hMediumdevalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion
CVE-2026-92708High· 7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job
CVE-2026-81176Medium· 5.3Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job