Executive brief
Svelte devalue is a JavaScript library used in server-side rendering frameworks like SvelteKit to serialize application data into HTML. When serializing Node Buffer objects, versions 5.1.0 through 5.9.2 leak up to 64 KB of unrelated process memory, including other users' request bodies and authentication headers. This occurs automatically during page rendering without requiring authentication, allowing attackers to extract sensitive information from concurrent requests.
Technical details
The stringify, stringifyAsync, and uneval functions serialize typed arrays by emitting their entire backing ArrayBuffer rather than only the visible view. Node Buffers share a process-wide allocation pool, so serializing a small Buffer discloses adjacent unrelated memory. The vulnerability fires on every server-side render and bypasses the library's parse/unflatten guards since serialization occurs before parsing. Fixed in version 5.9.3 by serializing only visible Buffer bytes.
Affected products
- Svelte devalue 5.1.0 through 5.9.2
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched: version 5.9.3