CVE-2026-42570

HIGH7.5

Svelte devalue: DoS via sparse array deserialization

Published: 5/14/2026Modified: 5/14/2026
Also known as:GHSA-77vg-94rm-hx3p

Description

`devalue.parse` could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (4)