LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-30226

svelte · devalue

Published
CVSS7.5
Severityhigh
WeaknessCWE-1321
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In devalue v5.6.3 and earlier, devalue.parse and devalue.unflatten were susceptible to prototype pollution via maliciously crafted payloads. Successful exploitation could lead to Denial of Service (DoS) or type confusion. This vulnerability is fixed in 5.6.4.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-30226

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-30226.