VendorsSveltedevalueall versions
Vulnerabilities

Svelte devalue

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2026-42570
Svelte devalue: DoS via sparse array deserialization
Published 2026-06-09 · Modified
7.5EPSS 0.007
CVE-2026-22774
devalue vulnerable to denial of service due to memory exhaustion in devalue.parse
Published 2026-01-15 · Modified
7.5EPSS 0.006
CVE-2026-22775
devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse
Published 2026-01-15 · Modified
7.5EPSS 0.006
CVE-2026-30226
devalue has prototype pollution in devalue.parse and devalue.unflatten
Published 2026-03-11 · Analyzed
7.5EPSS 0.005