Junglewise Threat Intelligence

devalue uneval sparse-array CPU amplification

Severity: medium · CVSS 4 · Published 2026-10-01

Technologies: devalue (npm), Svelte Devalue. Vendors: npm, Svelte.

Executive brief

Devalue is a JavaScript library used to serialize data structures. The uneval function performs work proportional to a sparse array's declared length, allowing an attacker to cause event-loop blocking and denial of service. Exploitation is difficult because creating attacker-controlled sparse arrays is hard in practice.

Technical details

The uneval function has inefficient algorithmic complexity when processing sparse arrays, iterating through the full declared length rather than only enumerable elements (CWE-407). An attacker who can pass sparse arrays to uneval can trigger excessive synchronous work, causing event-loop blocking. The vulnerability was patched in version 5.9.3 by avoiding eager sparse array allocation and scanning array holes.

Affected products

  • Svelte devalue <= 5.9.2

Timeline

  • 2026-10-01: disclosed
  • 2026-09-18: patched: Fixed in version 5.9.3

References

Related threats