Vulnerabilities/

Svelte devalue: DoS via sparse array deserialization

Severity:
High

Description

devalue.parse could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption.

Recommendation

Update the devalue package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
devalue
Anything's wrong? Let us know Last updated on May 15, 2026