Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-22774

28
FAUCET Score

CVE-2026-22774 is a denial-of-service vulnerability affecting Svelte devalue versions 5.3.0 to 5.6.1, where specially crafted input can cause excessive CPU and memory consumption during parsing. This high-severity vulnerability (CVSS 7.5) can be exploited remotely with low attack complexity, potentially leading to system unavailability. There is no evidence of active exploitation, and no public exploit code is available, though it has garnered some community discussion and media coverage. Organizations using affected versions should upgrade to 5.6.2 immediately to mitigate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.3.0, < 5.6.2CPE matchmatch criteria
cpe:2.3:a:svelte:devalue:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.57%
Probability of exploitation in next 30 days
EPSS Percentile
43.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0057 is in the 21st percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: devalueFixed in: 5.6.2
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Artifact Signer 1.2Fixed in: rhtas/rekor-search-ui-rhel9:sha256:1e3a46ade52215e2c78df9229f36301c94099e8397ee74ab99fb8bd504ce7aa2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Artifact Signer 1.3Fixed in: rhtas/rekor-search-ui-rhel9:sha256:3971738912069448174202486b61ed384153ca18af3e8430a55795a6e65eb58d
View patch
redhatno patchvia redhat_api
Product: Red Hat Build of Podman Desktop - Tech PreviewFixed in: rhdesktop/rh-podman-desktop-ext-bootc-rhel10

Vendor Advisories (2)

redhatCVE-2026-22774Important

devalue: devalue: Denial of Service due to excessive resource consumption from untrusted input

Jan 15, 2026
npmGHSA-vw5p-8cq8-m7mvhigh

Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parse

Jan 15, 2026

References

access.redhat.com / errata/RHSA-2026:2144
access.redhat.com / errata/RHSA-2026:2926
access.redhat.com / security/cve/CVE-2026-22774
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-22774.json
github.com / sveltejs/devalue/commit/e46afa64dd2b25aa35fb905ba5d20cea63aabbf7
Patch
github.com / sveltejs/devalue/releases/tag/v5.6.2
Release Notes
github.com / sveltejs/devalue/security/advisories/GHSA-vw5p-8cq8-m7mv
Vendor Advisory