CyberRota Analysis
AI-GeneratedThe Svelte devalue library in Java versions 5.1.0 through 5.9.2 is vulnerable due to improper serialization of typed arrays, which can inadvertently expose up to 64 KB of unrelated process memory, including sensitive information like request bodies and Authorization headers. This vulnerability is particularly critical for applications using server-side rendering frameworks such as SvelteKit or Nuxt, where public pages can unintentionally leak user data. Organizations utilizing these affected versions should prioritize upgrading to version 5.9.3 or implementing the recommended workaround to mitigate potential data exposure risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing ArrayBuffer rather than only the view, so serializing a Node Buffer, whose backing store is a process-wide shared pool, discloses up to 64 KB of unrelated process memory, including bytes from other in-flight requests. In a server-side-rendered framework such as SvelteKit or Nuxt, a public page whose load() returns a small Buffer, or that reads a small file, can therefore ship another user's request body or Authorization header in its HTML without authentication. Because this occurs during serialization, it fires on every such render and is not mitigated by the parse/unflatten prototype-pollution and denial-of-service guards, which only apply when parsing untrusted input. As a workaround, convert Node Buffer objects to Uint8Array before serialization. This issue has been fixed in version 5.9.3.