devalue
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting devaluepage 1 of 1
- CVE-2025-57820HIGHCVSS 7.9EG 0.0✓ Fixed in 5.3.22025-08-26
Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object with a __proto__ property and devalue.parse does not check that an index is numeric. This could result in assigning pro…
- CVE-2026-22774HIGHCVSS 7.5EG 7.5✓ Fixed in 5.6.22026-01-15
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potential…
- CVE-2026-22775HIGHCVSS 7.5EG 7.5✓ Fixed in 5.6.22026-01-15
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.1.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potential…
Check whether devalue is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for devalue CVEs against the assets you own.
Start Free Scan →