Junglewise Threat Intelligence

devalue quadratic expansion in uneval

Severity: high · Published 2026-10-01

Technologies: devalue (npm). Vendors: npm.

Executive brief

Devalue is a JavaScript serialization library used by Svelte for converting data structures to code. A flaw in its uneval function can cause a small input payload to expand into an extremely large serialized string when the input contains repeated primitive strings, leading to denial of service through resource exhaustion.

Technical details

The vulnerability is a quadratic expansion flaw (CWE-400 uncontrolled resource consumption, CWE-409 data amplification) in the uneval function that processes previously parsed data. When an attacker supplies crafted input with repeated primitive strings, the algorithm inefficiently expands them, potentially consuming excessive memory and CPU. This requires high attack complexity and specific deployment conditions (AT:P), but can be exploited over the network with no authentication required.

Affected products

  • sveltejs devalue 5.9.2 and earlier

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: patched: version 5.9.3 released
  • 2026-10-01: advisory

References

Related threats