OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-92708

HIGH · CVSS 7.5 EPSS 0.73% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Svelte devalue library in Java versions 5.1.0 through 5.9.2 is vulnerable due to improper serialization of typed arrays, which can inadvertently expose up to 64 KB of unrelated process memory, including sensitive information like request bodies and Authorization headers. This vulnerability is particularly critical for applications using server-side rendering frameworks such as SvelteKit or Nuxt, where public pages can unintentionally leak user data. Organizations utilizing these affected versions should prioritize upgrading to version 5.9.3 or implementing the recommended workaround to mitigate potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-92708
Severity
HIGH
CVSS
7.5
EPSS
0.73%
Java

Original NVD Description

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing ArrayBuffer rather than only the view, so serializing a Node Buffer, whose backing store is a process-wide shared pool, discloses up to 64 KB of unrelated process memory, including bytes from other in-flight requests. In a server-side-rendered framework such as SvelteKit or Nuxt, a public page whose load() returns a small Buffer, or that reads a small file, can therefore ship another user's request body or Authorization header in its HTML without authentication. Because this occurs during serialization, it fires on every such render and is not mitigated by the parse/unflatten prototype-pollution and denial-of-service guards, which only apply when parsing untrusted input. As a workaround, convert Node Buffer objects to Uint8Array before serialization. This issue has been fixed in version 5.9.3.