GHSA-wf3x-273g-mvxvLow▾ Sunlitdevalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Evaluating legitimate uneval output for a sparse array can allocate memory proportional to its declared length. A tiny serialized value can therefore cause large memory allocation in a consuming browser/runtime. This occurs during evaluation of generated code, not in default parse sparse-array construction.
You would only be affected by this if you were serializing very large sparse arrays and then evaluating the results. In the general use case for uneval of sending data to the client, the worst that could happen is the browser tab running out of memory.
devalue >= 1.0.0, <= 5.9.2Upgrade to a patched release:
devalue 5.9.3Connected by shared product, vendor, weakness, or advisory.
GHSA-hx4r-w6wj-j8fgMediumdevalue: Residual sparse-array CPU amplification in uneval
GHSA-mcm9-63f2-9j32Highdevalue: Repeated primitive strings cause quadratic expansion in uneval
GHSA-x5rw-q4pp-hg5gHighdevalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
GHSA-4q55-j62x-fr9hMediumdevalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion
CVE-2026-92708High· 7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job
CVE-2026-81176Medium· 5.3Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job