{"id":"GHSA-wf3x-273g-mvxv","summary":"devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated","details":"Evaluating legitimate `uneval` output for a sparse array can allocate memory proportional to its declared length. A tiny serialized value can therefore cause large memory allocation in a consuming browser/runtime. This occurs during evaluation of generated code, not in default `parse` sparse-array construction.\n\nYou would only be affected by this if you were serializing very large sparse arrays and then evaluating the results. In the general use case for `uneval` of sending data to the client, the worst that could happen is the browser tab running out of memory.","modified":"2026-10-01T15:30:13.280047533Z","published":"2026-10-01T15:17:13Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-10-01T15:17:13Z","nvd_published_at":null,"cwe_ids":["CWE-400","CWE-789"]},"references":[{"type":"WEB","url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-wf3x-273g-mvxv"},{"type":"WEB","url":"https://github.com/sveltejs/devalue/commit/6861dbbb7e548849e48bce718e88747a298f7250"},{"type":"PACKAGE","url":"https://github.com/sveltejs/devalue"},{"type":"WEB","url":"https://github.com/sveltejs/devalue/releases/tag/v5.9.3"}],"affected":[{"package":{"name":"devalue","ecosystem":"npm","purl":"pkg:npm/devalue"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0"},{"fixed":"5.9.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 5.9.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-wf3x-273g-mvxv/GHSA-wf3x-273g-mvxv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L"}]}