CVE-2026-42570General(svelte / devalue)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.parse could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption. This issue has been patched in version 5.8.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • devalue

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
devalue

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-15: 1Technical Details · 2026-05-15: 105-15
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Sanchit Jain@undiluted7027
    General

    @astrodotbuild there's a level 7.5 High CVE-2026-42570 vulnerability in the latest version. Any plans to patch it?

    Post summary

    The tweet references CVE-2026-42570 with a 7.5 severity rating and inquires about patch plans, but provides no further technical details or remediation information.

    0000040
    4 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsveltedevalue-node.js-

Explore more