Junglewise Threat Intelligence

devalue uncontrolled ArrayBuffer allocation in custom revivers

Severity: medium · CVSS 4 · Published 2026-10-01

Technologies: devalue (npm), Svelte Devalue. Vendors: npm, Svelte.

Executive brief

devalue is a JavaScript library used to serialize and deserialize complex data structures. A vulnerability allows attackers to create extremely large ArrayBuffers in memory using specially crafted input and custom reviver functions, potentially causing memory exhaustion or denial of service.

Technical details

The vulnerability exists in the parse() function when custom ArrayBuffer revivers are used; insufficient validation of typed-array backing buffers allows creation of massive allocations from minimal input. An attacker can exploit this via network vectors by providing malformed data to applications that deserialize untrusted input with devalue. The issue was patched in version 5.9.3 by validating backing buffers before typed array construction.

Affected products

  • Svelte devalue <= 5.9.2

Timeline

  • 2026-10-01: disclosed
  • 2026-10-01: patched: Fixed in version 5.9.3

References

Related threats