Denial of Service Vulnerability in Svelte JavaScript Library
CVE-2026-22774
7.5HIGH
What is CVE-2026-22774?
A vulnerability in the Svelte devalue JavaScript library allows an attacker to exploit devalue.parse with crafted inputs, leading to excessive CPU and memory usage. The issue arises from the method's failure to verify the type of input before processing, resulting in potential Denial of Service (DoS) on systems parsing untrusted data. This problem affects versions 5.3.0 to 5.6.1 and has been resolved in version 5.6.2. Developers are encouraged to update to the latest version to mitigate any risk.
Affected Version(s)
devalue >= 5.3.0, < 5.6.2
