Skip to content

Conversation

@aikido-autofix
Copy link
Contributor

@aikido-autofix aikido-autofix bot commented Feb 2, 2026

Patch critical DoS vulnerabilities in devalue.parse by fixing ArrayBuffer and typed array input validation to prevent resource exhaustion attacks

✅ 2 CVEs resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-22775
HIGH
Svelte devalue library has a DoS vulnerability where maliciously crafted inputs can cause excessive CPU/memory consumption during parsing, potentially enabling denial of service attacks on systems processing untrusted data.
CVE-2026-22774
HIGH
Svelte devalue library has a DoS vulnerability where maliciously crafted input can cause excessive CPU/memory consumption during parsing, potentially enabling denial of service attacks on systems processing untrusted data.

@gecBurton gecBurton merged commit 02eff00 into main Feb 6, 2026
10 checks passed
@gecBurton gecBurton deleted the fix/aikido-security-update-packages-15246202-m7iU branch February 6, 2026 10:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants