PT-2026-95695 · Devalue+2 · Devalue+2

CVE-2026-92708

·

Published

2026-09-18

·

Updated

2026-09-23

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Svelte devalue versions 5.1.0 through 5.9.2
Description The stringify() and uneval() functions serialize typed arrays by emitting the entire backing ArrayBuffer instead of only the view. When serializing a Node Buffer, which uses a process-wide shared pool, this can disclose up to 64 KB of unrelated process memory, potentially including data from other concurrent requests such as request bodies or Authorization headers. In server-side-rendered frameworks like SvelteKit or Nuxt, this may result in sensitive information being included in the HTML of a public page without authentication. This issue occurs during serialization and is not prevented by existing prototype-pollution or denial-of-service guards.
Recommendations Update to version 5.9.3. As a temporary workaround, convert Node Buffer objects to Uint8Array before serialization.

Exploit

Fix

DoS

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92708
GHSA-J22F-VQ7H-C4QM

Affected Products

Nuxt
Sveltekit
Devalue