PatchSiren cyber security CVE debrief
CVE-2026-22775 Svelte CVE debrief
CVE-2026-22775 is a denial of service vulnerability in Svelte Devalue, a JavaScript library for serializing values into strings. The vulnerability affects Devalue versions from 5.1.0 to 5.6.1 and can cause excessive CPU time and/or memory consumption when parsing input from untrusted sources. This can lead to denial of service in systems that use Devalue to parse externally-supplied data. The root cause of the vulnerability is the ArrayBuffer hydration expecting base64 encoded strings as input, but not checking the assumption before decoding the input. The vulnerability is fixed in Devalue version 5.6.2.
- Vendor
- Svelte
- Product
- Devalue
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-15
- Original CVE updated
- 2026-07-15
- Advisory published
- 2026-01-15
- Advisory updated
- 2026-07-15
Who should care
Developers and administrators who use Svelte Devalue in their applications should be aware of this vulnerability. This vulnerability can affect applications that parse input from untrusted sources, potentially leading to denial of service. Users of Devalue versions from 5.1.0 to 5.6.1 should take action to mitigate this vulnerability.
Technical summary
The Svelte Devalue library is vulnerable to a denial of service attack due to excessive CPU time and/or memory consumption when parsing certain inputs. The vulnerability exists in Devalue versions from 5.1.0 to 5.6.1 and is caused by the ArrayBuffer hydration expecting base64 encoded strings as input, but not checking the assumption before decoding the input. This can lead to denial of service in systems that use Devalue to parse externally-supplied data. The vulnerability has a CVSS score of 7.5 and is considered high severity. The vulnerability is fixed in Devalue version 5.6.2.
Defensive priority
High priority should be given to mitigating this vulnerability, as it can lead to denial of service in systems that use Devalue to parse externally-supplied data. Administrators and developers should take action to upgrade to Devalue version 5.6.2 or later.
Recommended defensive actions
- Upgrade to Devalue version 5.6.2 or later
- Review and validate input data to prevent excessive CPU time and/or memory consumption
- Implement compensating controls to detect and prevent denial of service attacks
- Monitor systems for signs of denial of service attacks
- Consider implementing additional security measures to protect against similar vulnerabilities
Evidence notes
The vulnerability is documented in the CVE-2026-22775 record and the NVD detail page. The vulnerability is caused by the ArrayBuffer hydration expecting base64 encoded strings as input, but not checking the assumption before decoding the input. The vulnerability affects Devalue versions from 5.1.0 to 5.6.1 and is fixed in Devalue version 5.6.2.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-22775 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-22775
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-22775 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-22775
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/sveltejs/devalue/commit/11755849fa0634ae294a15ec0aef2f43efcad7c4
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/sveltejs/devalue/releases/tag/v5.6.2
[email protected] - Release Notes
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/sveltejs/devalue/security/advisories/GHSA-g2pg-6438-jwpf
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:2144
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:2926
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-22775
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.