Medium · 4.9 Node.js & npm GHSA-j22f-vq7h-c4qm CVE-2026-92708 GHSA-9rgm-9g3h-6x36 CVE-2026-81176
Two devalue Vulnerabilities Patched: Memory Disclosure and DoS Risk in Svelte's Serialization Library
The devalue npm package, used to serialize values in SvelteKit, Nuxt and other frameworks, had two separate flaws: a high-severity memory disclosure bug (CVE-2026-92708) that could leak up to 64 KB of unrelated process memory, and a lower-severity denial-of-service issue (CVE-2026-81176) from unbounded parsing of untrusted input. Both are fixed in current releases.
AI summary
Svelte's devalue library, used to serialize values into strings for server-side rendering in frameworks such as SvelteKit and Nuxt, has received fixes for two distinct vulnerabilities disclosed in September and October 2026. The more severe issue allows unauthenticated disclosure of unrelated process memory during normal page rendering, while the second issue permits a denial-of-service condition when parsing untrusted serialized data.
What happened
Two vulnerabilities were identified in devalue, a JavaScript library that serializes values into strings when JSON.stringify is insufficient. CVE-2026-92708 affects the stringify and uneval functions: when serializing a typed array, devalue emitted the entire backing ArrayBuffer rather than just the relevant view. Because Node's Buffer objects are backed by a process-wide shared memory pool, serializing even a small Buffer could expose up to 64 KB of unrelated process memory, including data from other in-flight requests. Separately, CVE-2026-81176 affects devalue.parse, which failed to reject out-of-bounds indices greater than or equal to values.length. A crafted payload could exploit this to force quadratic processing cost as payload size grows, leading to denial of service when parsing untrusted devalue data.
Technical cause
For CVE-2026-92708, the root cause is that devalue's serialization logic for typed arrays captured the full underlying ArrayBuffer instead of the view's own bounds. Node Buffer objects frequently share a single larger backing pool for efficiency, so emitting the whole buffer leaks adjacent memory that was never intended to be part of the serialized value. This occurs purely during serialization and is not affected by existing prototype-pollution or DoS guards in the parser, since those only apply to parsing untrusted input, not to stringify/uneval output. For CVE-2026-81176, the parser in src/parse.js did not validate that array indices stayed within bounds (less than values.length). An attacker-controlled payload could exploit this to cause the parser to alternate between array representations, resulting in quadratic processing time relative to payload size.
Why it matters
In server-side-rendered applications built with frameworks like SvelteKit or Nuxt, a public page that returns a small Buffer from its load() function, or reads a small file, could unintentionally leak another user's request body or Authorization header directly in the page HTML, without any authentication required. This can happen on every render of the affected page, making it a persistent and silent information disclosure risk rather than a one-off occurrence. The DoS issue separately allows an attacker to degrade application availability by submitting crafted devalue payloads that are expensive to parse.
Who is affected
Any application or service using the devalue npm package is potentially affected, including those using it indirectly through frameworks such as SvelteKit or Nuxt for server-side rendering. For CVE-2026-92708, applications are at risk if they serialize Node Buffer objects (or other typed arrays backed by shared memory pools) via devalue's stringify or uneval functions. For CVE-2026-81176, applications that use devalue.parse to process untrusted or externally supplied serialized data are at risk.
Affected versions
CVE-2026-92708 affects devalue versions from 5.1.0 through 5.9.2 inclusive. CVE-2026-81176 affects devalue versions prior to 5.9.1 (i.e., all versions from 0 up to but not including 5.9.1).
Fixes and mitigation
CVE-2026-92708 is fixed in devalue version 5.9.3. As a workaround prior to upgrading, applications can convert Node Buffer objects to Uint8Array before serialization to avoid exposing the shared backing memory. CVE-2026-81176 is fixed in devalue version 5.9.2, which adds bounds checking to reject out-of-bounds indices during parsing.
Recommended action
Upgrade devalue to version 5.9.3 or later, which addresses both vulnerabilities. If an immediate upgrade is not possible, apply the documented workaround of converting Node Buffer objects to Uint8Array before serialization to mitigate CVE-2026-92708, and avoid parsing untrusted devalue data until patched to reduce exposure to CVE-2026-81176. Review server-side-rendered pages for any load() functions or file reads that return Buffer objects, as these may have been silently leaking data.
PatchBriefing score
4.9 / 10 · Medium
Official CVSS: 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Why this score
CVE-2026-92708 carries a CVSS score of 7.5 (High), reflecting a network-exploitable, unauthenticated, no-user-interaction vulnerability with high confidentiality impact (an attacker can read sensitive data) but no impact on integrity or availability. Its PatchBriefing score of 4.9 reflects this CVSS base score combined with the absence of known exploitation or public exploit code, and accounts for the fact that a fix is already available. CVE-2026-81176 has a CVSS score of 5.3 (Medium), reflecting a network-exploitable, unauthenticated DoS condition with low availability impact and no confidentiality or integrity impact. Its PatchBriefing score of 3.7 similarly reflects the absence of known or public exploitation and the availability of a fix. Neither vulnerability is listed as known exploited or associated with ransomware activity, and no public exploit code has been reported for either.
Affected versions
- devalue >= 5.1.0, <= 5.9.2
- vulnerable
- ≥ 5.9.3
- patched
- devalue < 5.9.1
- vulnerable
- ≥ 5.9.2
- patched
Reported fixes
CVE-2026-92708 is fixed in devalue version 5.9.3. As a workaround prior to upgrading, applications can convert Node Buffer objects to Uint8Array before serialization to avoid exposing the shared backing memory. CVE-2026-81176 is fixed in devalue version 5.9.2, which adds bounds checking to reject out-of-bounds indices during parsing.
How this was built
4 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email