{"id":"GHSA-33hq-fvwr-56pm","aliases":[],"url":"https://o3.security/vulnerability/GHSA-33hq-fvwr-56pm","summary":"devalue affected by CPU and memory amplification from sparse arrays","details":"Under certain circumstances, serializing sparse arrays using `uneval` or `stringify` could cause CPU and/or memory exhaustion. When this occurs on the server, it results in a DoS. This is extremely difficult to take advantage of in practice, as an attacker would have to manage to create a sparse array on the server — which is impossible in every mainstream wire format — and then that sparse array would have to be run through `uneval` or `stringify`.","published":"2026-02-19T20:29:30Z","modified":"2026-02-22T23:20:56.552579Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"devalue","fixedVersion":"5.6.3"}],"fix":{"url":"https://github.com/sveltejs/devalue/commit/819f1ac7475ab37547645cfb09bf2f678a799cf0","label":"sveltejs/devalue@819f1ac"},"references":[{"type":"WEB","url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-33hq-fvwr-56pm"},{"type":"WEB","url":"https://github.com/sveltejs/devalue/commit/819f1ac7475ab37547645cfb09bf2f678a799cf0"},{"type":"PACKAGE","url":"https://github.com/sveltejs/devalue"},{"type":"WEB","url":"https://github.com/sveltejs/devalue/releases/tag/v5.6.3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-22T23:20:56.552579Z"}}