Listen to this Post
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify is not sufficient, handling cyclical references, repeated references, and undefined. The vulnerability resides in the devalue.parse function within src/parse.js. Prior to version 5.9.3, devalue.parse fails to reject out-of-bounds indices that are greater than or equal to values.length. This omission allows a specially crafted untrusted payload to manipulate the parser into alternating between different array representations during processing. Each alternation forces the parser to perform work that grows quadratically with the payload size, rather than linearly. When such a payload is subsequently passed to the uneval function, the effect is amplified. Under very constrained circumstances, data that was parsed and then passed to uneval could turn a small payload into a very large serialized string. The uneval function is designed to take a JavaScript value and return the JavaScript code to create an equivalent value, essentially performing the reverse of eval. Because uneval must serialize the entire structure, the repeated primitive strings and the alternating array representations cause the serialization process to generate output whose size expands dramatically. This expansion consumes excessive CPU and memory resources. When this occurs on a server that processes untrusted devalue data, it results in a denial of service. The vulnerability has been assigned CVE-2026-81176 and is tracked under GitHub Advisory GHSA-mcm9-63f2-9j32. The NVD lists a CVSS 3.1 base score of 5.3 (Medium) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L, indicating a low impact on availability. However, the GitHub Advisory Database rates the severity as High. The issue is fixed in version 5.9.3, where out-of-bounds indices are properly rejected before array manipulation occurs, eliminating the quadratic work behavior. Applications are potentially affected if they call devalue.parse with untrusted data and subsequently pass the parsed result to uneval.
DailyCVE Form:
Platform: sveltejs/devalue
Version: before 5.9.3
Vulnerability: Quadratic uneval expansion
Severity: High severity
date: Sep 18 2026
Prediction: Patch mid October
What Undercode Say
npm install [email protected]
const devalue = require('devalue');
// Crafted payload with out-of-bounds indices
const malicious = '[{"a":0},{"a":1},{"a":2},{"a":0}]';
// Parse the untrusted payload
const parsed = devalue.parse(malicious);
// Pass to uneval, triggering quadratic expansion
const serialized = devalue.uneval(parsed);
console.log('Output length:', serialized.length);
Exploit: (Educational Purposes!)
// Generate a payload that alternates array representations
function buildPayload(size) {
let s = '[';
for (let i = 0; i < size; i++) {
s += <code>{"a":${i % 2}},</code>;
}
s += ']';
return s;
}
const payload = buildPayload(100000);
const parsed = devalue.parse(payload);
const result = devalue.uneval(parsed);
// Result size grows quadratically
Protection: from this CVE
Upgrade devalue to version 5.9.3 or later. Avoid calling devalue.parse with untrusted input. Validate and sanitize all data before parsing. Implement resource limits on server-side parsing operations.
Impact:
Denial of service via CPU and memory exhaustion. Small payloads can cause disproportionate resource consumption, leading to application unavailability.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

