PT-2026-93901 · Npm · Devalue

CVE-2026-81176

·

Published

2026-09-16

·

Updated

2026-10-01

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Svelte devalue versions prior to 5.9.2
Description Svelte devalue is a JavaScript library used to serialize values into strings. The devalue.parse() function in src/parse.js fails to reject out-of-bounds indices that are greater than or equal to values.length. An attacker can provide a specially crafted untrusted payload that forces the parser to alternate between array representations. This results in quadratic work as the payload size increases, leading to a denial of service in applications that parse untrusted data.
Recommendations Update Svelte devalue to version 5.9.2.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81176
GHSA-9RGM-9G3H-6X36

Affected Products

Devalue