Executive brief
Devalue is a JavaScript library used to serialize complex data structures. An attacker who can control input passed to the uneval function can cause the application's event loop to block by supplying a sparse array with a very large declared length, resulting in temporary unavailability of the application. This vulnerability is difficult to exploit in practice because creating such sparse arrays typically requires the attacker's direct code execution.
Technical details
The uneval function performs synchronous processing proportional to a sparse array's declared length rather than its actual content size, allowing a crafted sparse array to consume excessive CPU cycles and block the event loop. This is an inefficient algorithmic complexity issue (CWE-407) triggered when an application passes attacker-influenced array data to uneval without validation. A fix is available in version 5.9.3 and later.
Affected products
- Svelte.js devalue <= 5.9.2
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched: Version 5.9.3 released
- 2026-10-01: advisory