Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-22775

31
FAUCET Score

CVE-2026-22775 is a denial-of-service vulnerability affecting Svelte devalue versions 5.1.0 to 5.6.1. Maliciously crafted inputs to devalue.parse can lead to excessive CPU and/or memory consumption, impacting systems that process untrusted data. This vulnerability has a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity and without user interaction, resulting in high availability impact. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion, suggesting awareness among security researchers.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.1.0, < 5.6.2CPE matchmatch criteria
cpe:2.3:a:svelte:devalue:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.57%
Probability of exploitation in next 30 days
EPSS Percentile
43.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0057 is in the 21st percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: devalueFixed in: 5.6.2
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Artifact Signer 1.2Fixed in: rhtas/rekor-search-ui-rhel9:sha256:1e3a46ade52215e2c78df9229f36301c94099e8397ee74ab99fb8bd504ce7aa2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Artifact Signer 1.3Fixed in: rhtas/rekor-search-ui-rhel9:sha256:3971738912069448174202486b61ed384153ca18af3e8430a55795a6e65eb58d
View patch
redhatno patchvia redhat_api
Product: Red Hat Build of Podman Desktop - Tech PreviewFixed in: rhdesktop/rh-podman-desktop-ext-bootc-rhel10

Vendor Advisories (2)

npmGHSA-g2pg-6438-jwpfhigh

devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse

Jan 15, 2026
redhatCVE-2026-22775Important

devalue: devalue: Denial of Service due to improper input validation

Jan 15, 2026

References

access.redhat.com / errata/RHSA-2026:2144
access.redhat.com / errata/RHSA-2026:2926
access.redhat.com / security/cve/CVE-2026-22775
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-22775.json
github.com / sveltejs/devalue/commit/11755849fa0634ae294a15ec0aef2f43efcad7c4
Patch
github.com / sveltejs/devalue/releases/tag/v5.6.2
Release Notes
github.com / sveltejs/devalue/security/advisories/GHSA-g2pg-6438-jwpf
Vendor Advisory