Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.9 Node.js & npm GHSA-j22f-vq7h-c4qm CVE-2026-92708 GHSA-9rgm-9g3h-6x36 CVE-2026-81176

Two devalue Vulnerabilities Patched: Memory Disclosure and DoS Risk in Svelte's Serialization Library

The devalue npm package, used to serialize values in SvelteKit, Nuxt and other frameworks, had two separate flaws: a high-severity memory disclosure bug (CVE-2026-92708) that could leak up to 64 KB of unrelated process memory, and a lower-severity denial-of-service issue (CVE-2026-81176) from unbounded parsing of untrusted input. Both are fixed in current releases.

AI summary

Svelte's devalue library, used to serialize values into strings for server-side rendering in frameworks such as SvelteKit and Nuxt, has received fixes for two distinct vulnerabilities disclosed in September and October 2026. The more severe issue allows unauthenticated disclosure of unrelated process memory during normal page rendering, while the second issue permits a denial-of-service condition when parsing untrusted serialized data.

What happened

Two vulnerabilities were identified in devalue, a JavaScript library that serializes values into strings when JSON.stringify is insufficient. CVE-2026-92708 affects the stringify and uneval functions: when serializing a typed array, devalue emitted the entire backing ArrayBuffer rather than just the relevant view. Because Node's Buffer objects are backed by a process-wide shared memory pool, serializing even a small Buffer could expose up to 64 KB of unrelated process memory, including data from other in-flight requests. Separately, CVE-2026-81176 affects devalue.parse, which failed to reject out-of-bounds indices greater than or equal to values.length. A crafted payload could exploit this to force quadratic processing cost as payload size grows, leading to denial of service when parsing untrusted devalue data.

Technical cause

For CVE-2026-92708, the root cause is that devalue's serialization logic for typed arrays captured the full underlying ArrayBuffer instead of the view's own bounds. Node Buffer objects frequently share a single larger backing pool for efficiency, so emitting the whole buffer leaks adjacent memory that was never intended to be part of the serialized value. This occurs purely during serialization and is not affected by existing prototype-pollution or DoS guards in the parser, since those only apply to parsing untrusted input, not to stringify/uneval output. For CVE-2026-81176, the parser in src/parse.js did not validate that array indices stayed within bounds (less than values.length). An attacker-controlled payload could exploit this to cause the parser to alternate between array representations, resulting in quadratic processing time relative to payload size.

Why it matters

In server-side-rendered applications built with frameworks like SvelteKit or Nuxt, a public page that returns a small Buffer from its load() function, or reads a small file, could unintentionally leak another user's request body or Authorization header directly in the page HTML, without any authentication required. This can happen on every render of the affected page, making it a persistent and silent information disclosure risk rather than a one-off occurrence. The DoS issue separately allows an attacker to degrade application availability by submitting crafted devalue payloads that are expensive to parse.

Who is affected

Any application or service using the devalue npm package is potentially affected, including those using it indirectly through frameworks such as SvelteKit or Nuxt for server-side rendering. For CVE-2026-92708, applications are at risk if they serialize Node Buffer objects (or other typed arrays backed by shared memory pools) via devalue's stringify or uneval functions. For CVE-2026-81176, applications that use devalue.parse to process untrusted or externally supplied serialized data are at risk.

Affected versions

CVE-2026-92708 affects devalue versions from 5.1.0 through 5.9.2 inclusive. CVE-2026-81176 affects devalue versions prior to 5.9.1 (i.e., all versions from 0 up to but not including 5.9.1).

Fixes and mitigation

CVE-2026-92708 is fixed in devalue version 5.9.3. As a workaround prior to upgrading, applications can convert Node Buffer objects to Uint8Array before serialization to avoid exposing the shared backing memory. CVE-2026-81176 is fixed in devalue version 5.9.2, which adds bounds checking to reject out-of-bounds indices during parsing.

Recommended action

Upgrade devalue to version 5.9.3 or later, which addresses both vulnerabilities. If an immediate upgrade is not possible, apply the documented workaround of converting Node Buffer objects to Uint8Array before serialization to mitigate CVE-2026-92708, and avoid parsing untrusted devalue data until patched to reduce exposure to CVE-2026-81176. Review server-side-rendered pages for any load() functions or file reads that return Buffer objects, as these may have been silently leaking data.

PatchBriefing score

4.9 / 10 · Medium

Official CVSS: 7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Why this score

CVE-2026-92708 carries a CVSS score of 7.5 (High), reflecting a network-exploitable, unauthenticated, no-user-interaction vulnerability with high confidentiality impact (an attacker can read sensitive data) but no impact on integrity or availability. Its PatchBriefing score of 4.9 reflects this CVSS base score combined with the absence of known exploitation or public exploit code, and accounts for the fact that a fix is already available. CVE-2026-81176 has a CVSS score of 5.3 (Medium), reflecting a network-exploitable, unauthenticated DoS condition with low availability impact and no confidentiality or integrity impact. Its PatchBriefing score of 3.7 similarly reflects the absence of known or public exploitation and the availability of a fix. Neither vulnerability is listed as known exploited or associated with ransomware activity, and no public exploit code has been reported for either.

Affected versions

devalue >= 5.1.0, <= 5.9.2
vulnerable
≥ 5.9.3
patched
devalue < 5.9.1
vulnerable
≥ 5.9.2
patched

Reported fixes

CVE-2026-92708 is fixed in devalue version 5.9.3. As a workaround prior to upgrading, applications can convert Node Buffer objects to Uint8Array before serialization to avoid exposing the shared backing memory. CVE-2026-81176 is fixed in devalue version 5.9.2, which adds bounds checking to reject out-of-bounds indices during parsing.

How this was built

4 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
Two devalue Vulnerabilities Patched: Memory Disclosure and DoS Risk in Svelte's Serialization Library
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email