Impact
The devalue library mistakenly serializes any typed array as a full ArrayBuffer, so a Node Buffer’s shared backing store exposes unrelated data such as other users' request bodies or Authorization headers. Each render that serializes a Buffer can leak up to 64 KB of untrusted process memory without authentication, constituting a classic information exposure (CWE-200), misuse of process-scope storage (CWE-226), and inadequate handling of user‑controlled data (CWE-201).
Affected Systems
Svelte devalue library versions 5.1.0 through 5.9.2 are affected. Projects that embed devalue on the server—such as SvelteKit or Nuxt applications that serialize Buffers in load() or similar server‑side render paths—are vulnerable. The vendor is sveltejs:devalue.
Risk and Exploitability
With a CVSS score of 7.5 the flaw is high severity, but its EPSS score is less than 1%, indicating a low current exploitation probability. It is not listed in the CISA KEV catalog. An attacker can trigger the bug by causing a server‑side render that includes a user‑controlled or small Buffer; the flaw executes whenever serialization occurs and therefore repeatedly leaks memory.
OpenCVE Enrichment
Github GHSA