---
id: GHSA-wf3x-273g-mvxv
title: 'devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated'
summary: 'devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated'
severity: low
cwe:
  - CWE-400
  - CWE-789
vendor: devalue
product: devalue
ecosystem: npm
affected:
  - 'devalue >= 1.0.0, <= 5.9.2'
patched:
  - devalue 5.9.3
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:17:16Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-wf3x-273g-mvxv'
references:
  - url: >-
      https://github.com/sveltejs/devalue/security/advisories/GHSA-wf3x-273g-mvxv
  - url: >-
      https://github.com/sveltejs/devalue/commit/6861dbbb7e548849e48bce718e88747a298f7250
  - url: 'https://github.com/sveltejs/devalue/releases/tag/v5.9.3'
  - url: 'https://github.com/advisories/GHSA-wf3x-273g-mvxv'
tags:
  - ghsa
  - npm
ingestedAt: '2026-10-01T15:48:17.830Z'
---

## Overview

Evaluating legitimate `uneval` output for a sparse array can allocate memory proportional to its declared length. A tiny serialized value can therefore cause large memory allocation in a consuming browser/runtime. This occurs during evaluation of generated code, not in default `parse` sparse-array construction.

You would only be affected by this if you were serializing very large sparse arrays and then evaluating the results. In the general use case for `uneval` of sending data to the client, the worst that could happen is the browser tab running out of memory.

## Affected packages

- `devalue >= 1.0.0, <= 5.9.2`

## Remediation

Upgrade to a patched release:

- `devalue 5.9.3`
