Junglewise Threat Intelligence

devalue sparse arrays excessive memory allocation in uneval

Severity: medium · CVSS 4 · Published 2026-10-01

Technologies: devalue (npm), Svelte Devalue. Vendors: npm, Svelte.

Executive brief

devalue is a JavaScript library for serializing and deserializing data. When a sparse array is serialized and then evaluated, the deserialization process can allocate memory proportional to the array's declared length, allowing a small payload to cause excessive memory consumption in browsers or Node.js runtimes, potentially leading to denial of service.

Technical details

The uneval function emits sparse arrays in a form that triggers eager allocation during evaluation. When evaluated JavaScript code reconstructs these sparse arrays, it allocates memory for the full declared length regardless of actual element count. An attacker who controls serialized data can craft a tiny payload describing a very large sparse array, causing disproportionate memory allocation during deserialization.

Affected products

  • Svelte devalue 1.0.0 through 5.9.2

Timeline

  • 2026-10-01: disclosed
  • 2026-10-01: patched: Fixed in version 5.9.3

References

Related threats