{"id":"GHSA-9rgm-9g3h-6x36","summary":"Svelte devalue: DoS via malformed input","details":"### Impact\n\n`devalue.parse` prior to version 5.9.2 fails to reject out-of-bounds indices. Specially-crafted payloads can exploit this to cause devalue to alternate between different array representations, resulting in work that is quadratic with payload size.\n\nApplications are potentially affected if they call `devalue.parse` with untrusted data.\n\n### Patches\n\nThe bug is fixed in `devalue@5.9.2`.","aliases":["CVE-2026-81176"],"modified":"2026-09-17T20:45:04.992155900Z","published":"2026-09-17T20:28:21Z","database_specific":{"nvd_published_at":"2026-09-16T19:17:43Z","cwe_ids":["CWE-770"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-17T20:28:21Z"},"references":[{"type":"WEB","url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-9rgm-9g3h-6x36"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81176"},{"type":"WEB","url":"https://github.com/sveltejs/devalue/commit/8b2a4562c446d7c36d9d629778079a5fae4243e1"},{"type":"PACKAGE","url":"https://github.com/sveltejs/devalue"},{"type":"WEB","url":"https://github.com/sveltejs/devalue/releases/tag/v5.9.2"}],"affected":[{"package":{"name":"devalue","ecosystem":"npm","purl":"pkg:npm/devalue"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.9.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9rgm-9g3h-6x36/GHSA-9rgm-9g3h-6x36.json","last_known_affected_version_range":"\u003c 5.9.1"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}