THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9rgm-9g3h-6x36 (medium) — Svelte devalue: DoS via malformed input

[GHSA] GHSA-9rgm-9g3h-6x36 (medium) — Svelte devalue: DoS via malformed input

medgithub_advisoriesPublished 2026-09-17

GHSA-9rgm-9g3h-6x36 Severity: medium CVE: CVE-2026-81176

Svelte devalue: DoS via malformed input

### Impact

`devalue.parse` prior to version 5.9.2 fails to reject out-of-bounds indices. Specially-crafted payloads can exploit this to cause devalue to alternate between different array representations, resulting in work that is quadratic with payload size.

Applications are potentially affected if

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9rgm-9g3h-6x36