PT-2026-95695 · Devalue+2 · Devalue+2
CVE-2026-92708
·
Published
2026-09-18
·
Updated
2026-09-23
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Svelte devalue versions 5.1.0 through 5.9.2
Description
The
stringify() and uneval() functions serialize typed arrays by emitting the entire backing ArrayBuffer instead of only the view. When serializing a Node Buffer, which uses a process-wide shared pool, this can disclose up to 64 KB of unrelated process memory, potentially including data from other concurrent requests such as request bodies or Authorization headers. In server-side-rendered frameworks like SvelteKit or Nuxt, this may result in sensitive information being included in the HTML of a public page without authentication. This issue occurs during serialization and is not prevented by existing prototype-pollution or denial-of-service guards.Recommendations
Update to version 5.9.3.
As a temporary workaround, convert Node Buffer objects to Uint8Array before serialization.
Exploit
Fix
DoS
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nuxt
Sveltekit
Devalue