Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2232414
AlmaLinux
5964
Alpaquita
16124
Alpine
4635
Android
3677
Azure Linux
17766
BellSoft Hardened Containers
762
Bitnami
9476
Chainguard
1043084
CleanStart
5229
CRAN
14
crates.io
2747
Debian
68820
Echo
7685
GHC
3
GIT
108628
GitHub Actions
55
Go
9317
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6233
Maven
7048
MinimOS
147666
npm
229052
NuGet
1869
opam
29
openEuler
8900
openSUSE
14526
OSS-Fuzz
4015
Packagist
7100
Pub
11
PyPI
25416
Red Hat
23452
Rocky Linux
4332
Root
19620
RubyGems
5326
SUSE
23401
SwiftURL
60
TuxCare
9809
Ubuntu
65805
VSCode
21
Wolfi
292652
ID
Packages
Summary
Published
arrow_upward
Attributes
CLSA-2026-1790888237
TuxCare:npm/devalue
TuxCare security update for devalue (1 CVE)
4 hours ago
Fix available
CLSA-2026-1790888210
TuxCare:npm/devalue
TuxCare security update for devalue (5 CVEs)
4 hours ago
Fix available
GHSA-j22f-vq7h-c4qm
npm/devalue
devalue: `stringify`/`uneval` serialize shared memory
10 hours ago
Fix available
Severity - 7.5 (High)
GHSA-hx4r-w6wj-j8fg
npm/devalue
devalue: Residual sparse-array CPU amplification in uneval
10 hours ago
Fix available
Severity - 6.3 (Medium)
GHSA-mcm9-63f2-9j32
npm/devalue
devalue: Repeated primitive strings cause quadratic expansion in uneval
10 hours ago
Fix available
Severity - 8.2 (High)
GHSA-wf3x-273g-mvxv
npm/devalue
devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
10 hours ago
Fix available
Severity - 2.3 (Low)
GHSA-r9w8-h9r3-54w4
npm/devalue
devalue: Custom ArrayBuffer revivers can bypass typed-array allocation validation
10 hours ago
Fix available
Severity - 8.2 (High)
GHSA-x5rw-q4pp-hg5g
npm/devalue
devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
10 hours ago
Fix available
Severity - 8.2 (High)
GHSA-4q55-j62x-fr9h
npm/devalue
devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion
10 hours ago
Fix available
Severity - 6.3 (Medium)
CLSA-2026-1790606671
TuxCare:npm/devalue
TuxCare security update for devalue (2 CVEs)
3 days ago
Fix available
CLSA-2026-1790605435
TuxCare:npm/devalue
TuxCare security update for devalue (2 CVEs)
3 days ago
Fix available
CLSA-2026-1790161447
TuxCare:npm/devalue
TuxCare security update for devalue (2 CVEs)
23 Sep
Fix available
CVE-2026-92708
github.com/sveltejs/devalue
devalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval` serialize Node Buffers
18 Sep
Fix available
Severity - 7.5 (High)
CLSA-2026-1789752547
TuxCare:npm/devalue
TuxCare security update for devalue (2 CVEs)
18 Sep
Fix available
GHSA-9rgm-9g3h-6x36
npm/devalue
Svelte devalue: DoS via malformed input
17 Sep
Fix available
Severity - 5.3 (Medium)
CVE-2026-81176
github.com/sveltejs/devalue
Svelte devalue: DoS via malformed input
16 Sep
Fix available
Severity - 5.3 (Medium)
Load more...
Vulnerability Database - OSV