Junglewise Threat Intelligence

devalue uneval denial of service via sparse array

Severity: medium · Published 2026-10-01

Technologies: devalue (npm). Vendors: npm.

Executive brief

Devalue is a JavaScript library used to serialize complex data structures. An attacker who can control input passed to the uneval function can cause the application's event loop to block by supplying a sparse array with a very large declared length, resulting in temporary unavailability of the application. This vulnerability is difficult to exploit in practice because creating such sparse arrays typically requires the attacker's direct code execution.

Technical details

The uneval function performs synchronous processing proportional to a sparse array's declared length rather than its actual content size, allowing a crafted sparse array to consume excessive CPU cycles and block the event loop. This is an inefficient algorithmic complexity issue (CWE-407) triggered when an application passes attacker-influenced array data to uneval without validation. A fix is available in version 5.9.3 and later.

Affected products

  • Svelte.js devalue <= 5.9.2

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: patched: Version 5.9.3 released
  • 2026-10-01: advisory

References

Related threats