Skip to main content
Vulnerability Database/CVE-2026-81176

CVE-2026-81176: Svelte Devalue Parser DOS Vulnerability

CVE-2026-81176 is a denial of service vulnerability in Svelte devalue that allows attackers to cause quadratic work through crafted payloads. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-81176 Overview

CVE-2026-81176 is a denial-of-service vulnerability in Svelte devalue, a JavaScript serialization library used as an alternative to JSON.stringify when richer value types must be preserved. Versions prior to 5.9.2 fail to reject out-of-bounds indices in devalue.parse, allowing an attacker to craft payloads that trigger quadratic parsing work. Applications that deserialize untrusted devalue input can be forced to consume excessive CPU, degrading availability. The maintainers released a fix in devalue 5.9.2.

Critical Impact

A remote, unauthenticated attacker can submit a specially crafted payload that causes devalue.parse to perform quadratic work, exhausting CPU and producing denial of service in services that parse untrusted devalue data.

Affected Products

  • Svelte devalue versions prior to 5.9.2
  • Applications and frameworks (including SvelteKit-based services) that invoke devalue.parse on untrusted input
  • Server and client runtimes that deserialize devalue payloads originating from external clients

Discovery Timeline

Technical Details for CVE-2026-81176

Vulnerability Analysis

The devalue library serializes JavaScript values into a compact array-based representation, then reconstructs them during parse. Each entry in the encoded array may reference another entry by index, enabling cyclic and shared references. Prior to 5.9.2, src/parse.js did not validate that referenced indices fall within values.length. A crafted payload can alternate between representations that force the parser to re-enter hydration paths repeatedly, producing quadratic time complexity relative to payload size. This maps to [CWE-770] Allocation of Resources Without Limits or Throttling, expressed here as unbounded parser work rather than unbounded memory allocation.

Root Cause

The parser dereferences values[index] without checking whether index is within bounds. Out-of-bounds indices bypass the intended hydration-cache short-circuit (if (index in hydrated) return hydrated[index]) and drive the parser into repeated recomputation paths as it attempts to resolve non-existent entries.

Attack Vector

An attacker sends a crafted devalue payload to any endpoint that calls devalue.parse on untrusted input. No authentication or user interaction is required. Impact is limited to availability; confidentiality and integrity are not affected.

javascript
// Patch in src/parse.js — reject out-of-bounds indices before dereference
		if (index in hydrated) return hydrated[index];

+		if (index >= values.length) {
+			throw new Error(`Invalid input`);
+		}
+
		const value = values[index];

		if (!value || typeof value !== 'object') {

Source: GitHub Commit 8b2a4562. The fix rejects any index that is greater than or equal to values.length, preventing the parser from entering the quadratic path.

Detection Methods for CVE-2026-81176

Indicators of Compromise

  • Sustained high CPU utilization in Node.js processes correlated with inbound requests to endpoints that call devalue.parse.
  • HTTP requests carrying unusually large or structurally repetitive devalue-encoded bodies to SvelteKit form actions, load functions, or custom API routes.
  • Application logs showing Invalid input errors thrown from parse.js after upgrading, indicating rejected malformed payloads.

Detection Strategies

  • Inventory dependencies with npm ls devalue or pnpm why devalue to identify direct and transitive usage of versions below 5.9.2.
  • Instrument request handlers that invoke devalue.parse to record parse duration and payload size, and alert on outliers.
  • Add a Software Composition Analysis (SCA) rule that flags devalue < 5.9.2 in CI pipelines and container images.

Monitoring Recommendations

  • Track per-request CPU time and event-loop lag on Node.js services exposing devalue-consuming endpoints.
  • Monitor upstream reverse proxies for request-body size anomalies and elevated 5xx rates on affected routes.
  • Forward runtime and Web Application Firewall (WAF) telemetry into a centralized data lake to correlate payload patterns across services.

How to Mitigate CVE-2026-81176

Immediate Actions Required

  • Upgrade devalue to version 5.9.2 or later in all direct and transitive dependency trees.
  • Rebuild and redeploy SvelteKit applications and any Node.js services that call devalue.parse on untrusted input.
  • Enforce request body size limits at the reverse proxy or framework layer for endpoints that accept devalue payloads.

Patch Information

The fix is released in devalue 5.9.2. Details are available in the GitHub Security Advisory GHSA-9rgm-9g3h-6x36 and the GitHub Release v5.9.2. The corresponding source change is in commit 8b2a4562, which adds an explicit bounds check before dereferencing values[index].

Workarounds

  • Restrict devalue.parse to trusted producers only; do not parse payloads received directly from untrusted clients.
  • Apply strict maximum body-size and parse-time limits, and reject requests that exceed them before invoking the parser.
  • Place affected endpoints behind rate limiting to reduce the impact of repeated malicious payloads until patching completes.
bash
# Upgrade devalue to the fixed release
npm install devalue@^5.9.2

# Verify no vulnerable versions remain in the dependency tree
npm ls devalue

# Audit for known advisories
npm audit --production

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.