GHSA-77vg-94rm-hx3p

Suggest an improvement
Source
https://github.com/advisories/GHSA-77vg-94rm-hx3p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-77vg-94rm-hx3p/GHSA-77vg-94rm-hx3p.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-77vg-94rm-hx3p
Aliases
Published
2026-05-14T20:23:47Z
Modified
2026-06-09T18:45:22Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Svelte devalue: DoS via sparse array deserialization
Details

devalue.parse could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption.

Database specific
{
    "cwe_ids":  [
        "CWE-770"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-14T20:23:47Z",
    "nvd_published_at":  "2026-06-09T17:17:07Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / devalue

Package

Affected ranges

Type
SEMVER
Events
Introduced
5.6.3
Fixed
5.8.1

Database specific

last_known_affected_version_range
"<= 5.8.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-77vg-94rm-hx3p/GHSA-77vg-94rm-hx3p.json"