Impact
Svelte devalue is a JavaScript library that serializes values into strings. Prior to version 5.9.2, its parse function accepts out‑of‑bounds indices without rejection, which can cause the parser to alternate between array representations as the payload grows. This behavior results in quadratic computational work and can exhaust CPU resources, leading to denial of service. The flaw reflects vulnerabilities in parsing logic and uncontrolled resource consumption, as reflected by CWE‑1285 and CWE‑770.
Affected Systems
The affected product is the Svelte devalue library (sveltejs:devalue). Any version prior to 5.9.2 is vulnerable; the issue is resolved in v5.9.2 and later.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to supply a specially crafted untrusted payload that is parsed by devalue.parse, typically through user input or network data. When processed, the quadratic workload can degrade application responsiveness and potentially bring services down.
OpenCVE Enrichment
Github GHSA