mediumCVSS 5.3Vulnerability

CVE-2026-81176

### Impact `devalue.parse` prior to version 5.9.2 fails to reject out-of-bounds indices. Specially-crafted payloads can exploit this to cause devalue to alternate between different array representations, resulting in work that is quadratic with payload size. Applications are potentially affected if they call `devalue.parse` with untrusted data. ### Patches The bug is fixed in `[email protected]`.

Properties

ghsa_id
GHSA-9rgm-9g3h-6x36
severity
medium
summary
Svelte devalue: DoS via malformed input
cvss_score
5.3
cve_id
CVE-2026-81176
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
signal_observed_at
2026-09-17T21:32:39+00:00
is_ghsa_only
false
ghsa_published
2026-09-17T20:28:21Z
source_url
https://github.com/advisories/GHSA-9rgm-9g3h-6x36
ghsa_updated
2026-09-17T20:28:22Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Allocation of Resources Without Limits or Throttling

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/devalue

AFFECTS (1)

[Software]npm/devalue

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81176 (CVSS 5.3) — Ninja Signal Threat Intelligence | Ninja Signal