Review reviewHigh

CVE-2026-42570

sveltejs devalue, Red Hat Trusted Artifact Signer 1.4, Red Hat Build of Podman Desktop

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.parse could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption. This issue has been patched in version 5.8.1.

CVSS
7.5
EPSS
0.39%
32.0% percentile
CISA KEV
Not listed
Published
2026.06.10
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.39%
Technical severityCVSS 7.5

Vulnerability overview

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.parse could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption. This issue has been patched in version 5.8.1.

Affected product and versions

Product
sveltejs devalue, Red Hat Trusted Artifact Signer 1.4, Red Hat Build of Podman Desktop
Affected versions
>= >= 5.6.3, < 5.8.1, >= 5.6.3 < 5.8.1
Fixed versions
5.8.1

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that sveltejs devalue, Red Hat Trusted Artifact Signer 1.4, Red Hat Build of Podman Desktop and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-770
CVE-2026-42570 — sveltejs devalue, Red Hat Trusted Artifact Signer 1.4, Red Hat Build of Podman Desktop | SECUFOCUS NOW