<Vulnerability name="CVE-2026-81176">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-09-16T18:34:34</PublicDate>
    <Bugzilla id="2535592" url="https://bugzilla.redhat.com/show_bug.cgi?id=2535592" xml:lang="en:us">
devalue: Devalue: Denial of Service via malformed input parsing
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-1285</CWE>
    <Details xml:lang="en:us" source="Mitre">
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. Prior to 5.9.2, devalue.parse does not reject out-of-bounds indices that are greater than or equal to values.length in src/parse.js. A specially crafted untrusted payload can make the parser alternate between array representations, producing quadratic work as the payload grows and causing denial of service in applications that parse untrusted devalue data. This issue is fixed in version 5.9.2.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in the Svelte devalue library. An attacker can provide a specially crafted, untrusted payload to the `devalue.parse` function. This malformed input, specifically out-of-bounds indices, can cause the parser to perform quadratic work, leading to a denial of service (DoS) in applications that process such data.
    </Details>
    <PackageState cpe="cpe:/a:redhat:podman_desktop:1">
        <ProductName>Red Hat Build of Podman Desktop</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rh-podman-desktop.git</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhoai/odh-feature-server-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:trusted_artifact_signer:1">
        <ProductName>Red Hat Trusted Artifact Signer</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhtas/rekor-search-ui-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-81176
https://nvd.nist.gov/vuln/detail/CVE-2026-81176
https://github.com/sveltejs/devalue/commit/8b2a4562c446d7c36d9d629778079a5fae4243e1
https://github.com/sveltejs/devalue/releases/tag/v5.9.2
https://github.com/sveltejs/devalue/security/advisories/GHSA-9rgm-9g3h-6x36
    </References>
</Vulnerability>