CVE-2026-81176 Overview
CVE-2026-81176 is a denial-of-service vulnerability in Svelte devalue, a JavaScript serialization library used as an alternative to JSON.stringify when richer value types must be preserved. Versions prior to 5.9.2 fail to reject out-of-bounds indices in devalue.parse, allowing an attacker to craft payloads that trigger quadratic parsing work. Applications that deserialize untrusted devalue input can be forced to consume excessive CPU, degrading availability. The maintainers released a fix in devalue 5.9.2.
Critical Impact
A remote, unauthenticated attacker can submit a specially crafted payload that causes devalue.parse to perform quadratic work, exhausting CPU and producing denial of service in services that parse untrusted devalue data.
Affected Products
- Svelte devalue versions prior to 5.9.2
- Applications and frameworks (including SvelteKit-based services) that invoke devalue.parse on untrusted input
- Server and client runtimes that deserialize devalue payloads originating from external clients
Discovery Timeline
- 2026-09-16 - CVE-2026-81176 published to the National Vulnerability Database
- 2026-09-16 - Last updated in NVD database
- Fix released in devalue version 5.9.2 per the GitHub Release v5.9.2 and GitHub Security Advisory GHSA-9rgm-9g3h-6x36
Technical Details for CVE-2026-81176
Vulnerability Analysis
The devalue library serializes JavaScript values into a compact array-based representation, then reconstructs them during parse. Each entry in the encoded array may reference another entry by index, enabling cyclic and shared references. Prior to 5.9.2, src/parse.js did not validate that referenced indices fall within values.length. A crafted payload can alternate between representations that force the parser to re-enter hydration paths repeatedly, producing quadratic time complexity relative to payload size. This maps to [CWE-770] Allocation of Resources Without Limits or Throttling, expressed here as unbounded parser work rather than unbounded memory allocation.
Root Cause
The parser dereferences values[index] without checking whether index is within bounds. Out-of-bounds indices bypass the intended hydration-cache short-circuit (if (index in hydrated) return hydrated[index]) and drive the parser into repeated recomputation paths as it attempts to resolve non-existent entries.
Attack Vector
An attacker sends a crafted devalue payload to any endpoint that calls devalue.parse on untrusted input. No authentication or user interaction is required. Impact is limited to availability; confidentiality and integrity are not affected.
// Patch in src/parse.js — reject out-of-bounds indices before dereference
if (index in hydrated) return hydrated[index];
+ if (index >= values.length) {
+ throw new Error(`Invalid input`);
+ }
+
const value = values[index];
if (!value || typeof value !== 'object') {
Source: GitHub Commit 8b2a4562. The fix rejects any index that is greater than or equal to values.length, preventing the parser from entering the quadratic path.
Detection Methods for CVE-2026-81176
Indicators of Compromise
- Sustained high CPU utilization in Node.js processes correlated with inbound requests to endpoints that call devalue.parse.
- HTTP requests carrying unusually large or structurally repetitive devalue-encoded bodies to SvelteKit form actions, load functions, or custom API routes.
- Application logs showing Invalid input errors thrown from parse.js after upgrading, indicating rejected malformed payloads.
Detection Strategies
- Inventory dependencies with npm ls devalue or pnpm why devalue to identify direct and transitive usage of versions below 5.9.2.
- Instrument request handlers that invoke devalue.parse to record parse duration and payload size, and alert on outliers.
- Add a Software Composition Analysis (SCA) rule that flags devalue < 5.9.2 in CI pipelines and container images.
Monitoring Recommendations
- Track per-request CPU time and event-loop lag on Node.js services exposing devalue-consuming endpoints.
- Monitor upstream reverse proxies for request-body size anomalies and elevated 5xx rates on affected routes.
- Forward runtime and Web Application Firewall (WAF) telemetry into a centralized data lake to correlate payload patterns across services.
How to Mitigate CVE-2026-81176
Immediate Actions Required
- Upgrade devalue to version 5.9.2 or later in all direct and transitive dependency trees.
- Rebuild and redeploy SvelteKit applications and any Node.js services that call devalue.parse on untrusted input.
- Enforce request body size limits at the reverse proxy or framework layer for endpoints that accept devalue payloads.
Patch Information
The fix is released in devalue 5.9.2. Details are available in the GitHub Security Advisory GHSA-9rgm-9g3h-6x36 and the GitHub Release v5.9.2. The corresponding source change is in commit 8b2a4562, which adds an explicit bounds check before dereferencing values[index].
Workarounds
- Restrict devalue.parse to trusted producers only; do not parse payloads received directly from untrusted clients.
- Apply strict maximum body-size and parse-time limits, and reject requests that exceed them before invoking the parser.
- Place affected endpoints behind rate limiting to reduce the impact of repeated malicious payloads until patching completes.
# Upgrade devalue to the fixed release
npm install devalue@^5.9.2
# Verify no vulnerable versions remain in the dependency tree
npm ls devalue
# Audit for known advisories
npm audit --production
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
