Executive brief
devalue is a JavaScript library used to serialize data structures into executable code. When processing specially crafted data containing repeated primitive strings, the uneval function can expand the output to many times the input size, potentially causing performance degradation, denial of service, or memory exhaustion on applications that rely on this serialization.
Technical details
The uneval function exhibits quadratic expansion when processing data with repeated primitive strings, where a small input payload can be expanded into a disproportionately large serialized string output. This is a resource consumption vulnerability (CWE-400, CWE-409) affecting the parsing and serialization workflow. An attacker can craft inputs that trigger this amplification, leading to denial of service through memory exhaustion or CPU resource consumption.
Affected products
- Svelte devalue <= 5.9.2
Timeline
- 2026-10-01: disclosed
- 2026-10-01: patched: Fixed in version 5.9.3