All 7 CVE vulnerabilities found in devalue, with AI-generated Chinese analysis, references, and POCs.
Vendor: sveltejs
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-92708 | devalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval` serialize Node Buffers CWE-200 | 7.5 | High | 2026-09-18 |
| CVE-2026-81176 | Svelte devalue: DoS via malformed input CWE-770 | 5.3 | Medium | 2026-09-16 |
| CVE-2026-42570 | Svelte devalue: DoS via sparse array deserialization CWE-770 | 7.5 | High | 2026-06-09 |
| CVE-2026-30226 | devalue has prototype pollution in devalue.parse and devalue.unflatten CWE-1321 | 9.1AI | Critical AI | 2026-03-11 |
| CVE-2026-22775 | devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse CWE-405 | 7.5 | High | 2026-01-15 |
| CVE-2026-22774 | devalue vulnerable to denial of service due to memory exhaustion in devalue.parse CWE-405 | 7.5 | High | 2026-01-15 |
| CVE-2025-57820 | Svelte devalue vulnerable to prototype pollution CWE-1321 | 9.1AI | Critical AI | 2025-08-26 |
All 7 known CVE vulnerabilities affecting devalue with full Chinese analysis, references, and POCs where available.