Svelte devalue: DoS via sparse array deserialization
Description
Published to the GitHub Advisory Database
May 14, 2026
Reviewed
May 14, 2026
Published by the National Vulnerability Database
Jun 9, 2026
Last updated
Jun 9, 2026
devalue.parsecould, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption.References