Security Advisories์ถ์ฒ: GitHub Security Advisories์กฐํ์ 6
[devalue] devalue affected by CPU and memory amplification from sparse arrays
By GitHub2026๋
2์ 20์ผ
**[devalue] devalue affected by CPU and memory amplification from sparse arrays**
Under certain circumstances, serializing sparse arrays using uneval or stringify could cause CPU and/or memory exhaustion. When this occurs on the server, it results in a DoS. This is extremely difficult to take advantage of in practice, as an attacker would have to manage to create a sparse array on the server โ which is impossible in every mainstream wire format โ and then that sparse array would have to be run through uneval or stringify. References https://github.com/sveltejs/devalue/security/advisories/GHSA-33hq-fvwr-56pm https://github.com/sveltejs/devalue/commit/819f1ac7475ab37547645cfb09bf2f678a799cf0 https://github.com/sveltejs/devalue/releases/tag/v5.6.3 https://github.com/advisories/GHSA-33hq-fvwr-56pm
---
**[devsupporter ํด์ค]**
์ด ๊ธฐ์ฌ๋ GitHub Security Advisories์์ ์ ๊ณตํ๋ ์ต์ ๊ฐ๋ฐ ๋ํฅ์ ๋๋ค. ๊ด๋ จ ๋๊ตฌ๋ ๊ธฐ์ ์ ๋ํด ๋ ์์๋ณด์๋ ค๋ฉด ์๋ณธ ๋งํฌ๋ฅผ ์ฐธ๊ณ ํ์ธ์.
Under certain circumstances, serializing sparse arrays using uneval or stringify could cause CPU and/or memory exhaustion. When this occurs on the server, it results in a DoS. This is extremely difficult to take advantage of in practice, as an attacker would have to manage to create a sparse array on the server โ which is impossible in every mainstream wire format โ and then that sparse array would have to be run through uneval or stringify. References https://github.com/sveltejs/devalue/security/advisories/GHSA-33hq-fvwr-56pm https://github.com/sveltejs/devalue/commit/819f1ac7475ab37547645cfb09bf2f678a799cf0 https://github.com/sveltejs/devalue/releases/tag/v5.6.3 https://github.com/advisories/GHSA-33hq-fvwr-56pm
---
**[devsupporter ํด์ค]**
์ด ๊ธฐ์ฌ๋ GitHub Security Advisories์์ ์ ๊ณตํ๋ ์ต์ ๊ฐ๋ฐ ๋ํฅ์ ๋๋ค. ๊ด๋ จ ๋๊ตฌ๋ ๊ธฐ์ ์ ๋ํด ๋ ์์๋ณด์๋ ค๋ฉด ์๋ณธ ๋งํฌ๋ฅผ ์ฐธ๊ณ ํ์ธ์.
![[devalue] devalue affected by CPU and memory amplification from sparse arrays](/assets/images/github_com_1771583665614.png)