CVE-2026-22775

Publication date

2026-01-15 18:59:37

Family

GitHub_M

State

PUBLISHED

Description

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isnt sufficient for the job. From 5.1.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input from untrusted sources. This affects applications using devalue.parse on externally-supplied data. The root cause is the ArrayBuffer hydration expecting base64 encoded strings as input, but not checking the assumption before decoding the input. This vulnerability is fixed in 5.6.2.