Executive brief
Devalue is a JavaScript serialization library used by Svelte for converting data structures to code. A flaw in its uneval function can cause a small input payload to expand into an extremely large serialized string when the input contains repeated primitive strings, leading to denial of service through resource exhaustion.
Technical details
The vulnerability is a quadratic expansion flaw (CWE-400 uncontrolled resource consumption, CWE-409 data amplification) in the uneval function that processes previously parsed data. When an attacker supplies crafted input with repeated primitive strings, the algorithm inefficiently expands them, potentially consuming excessive memory and CPU. This requires high attack complexity and specific deployment conditions (AT:P), but can be exploited over the network with no authentication required.
Affected products
- sveltejs devalue 5.9.2 and earlier
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched: version 5.9.3 released
- 2026-10-01: advisory