sveltejs kit
6 known vulnerabilities in sveltejs kit, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-82261 CVSS 8.7 high SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion…
- CVE-2026-82260 CVSS 8.7 high SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form…
- CVE-2026-82259 CVSS 8.7 high SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote…
- CVE-2026-82258 CVSS 5.9 medium SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users…
- CVE-2026-82257 CVSS 5.3 medium SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept…
- CVE-2026-82256 CVSS 6.9 medium SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by…