CVE-2026-82261
- EPSS 0.34%
- Veröffentlicht 28.08.2026 10:49:44
- Zuletzt bearbeitet 08.10.2026 16:17:48
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send malformed form data to cause the server to become unresp...
CVE-2026-82260
- EPSS 0.34%
- Veröffentlicht 28.08.2026 10:49:43
- Zuletzt bearbeitet 08.10.2026 16:17:48
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause excess...
CVE-2026-82258
- EPSS 0.16%
- Veröffentlicht 28.08.2026 10:49:42
- Zuletzt bearbeitet 08.10.2026 16:17:48
SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploit specific timing conditions to access sensitive da...
CVE-2026-82259
- EPSS 0.37%
- Veröffentlicht 28.08.2026 10:49:42
- Zuletzt bearbeitet 08.10.2026 16:17:48
SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to process the fil...
CVE-2026-82257
- EPSS 0.21%
- Veröffentlicht 28.08.2026 10:49:41
- Zuletzt bearbeitet 08.10.2026 16:17:48
SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototy...
CVE-2026-82256
- EPSS 0.25%
- Veröffentlicht 28.08.2026 10:49:40
- Zuletzt bearbeitet 08.10.2026 16:17:48
SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly crashing the application proce...
CVE-2024-53261
- EPSS 0.32%
- Veröffentlicht 25.11.2024 20:15:10
- Zuletzt bearbeitet 28.08.2025 14:34:39
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. "Unsanitized input from *the request URL* flows into `end`, where it is used to render an HTML page returned to the user. This may result in a Cross-Sit...
CVE-2024-53262
- EPSS 0.47%
- Veröffentlicht 25.11.2024 20:15:10
- Zuletzt bearbeitet 28.08.2025 14:39:17
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html template for errors contains placeholders that are replaced without escaping the content first. error.html is the page that is ren...
CVE-2023-29008
- EPSS 0.37%
- Veröffentlicht 06.04.2023 17:15:10
- Zuletzt bearbeitet 21.11.2024 07:56:23
The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box cross-site request forgery (CSRF...
CVE-2023-29003
- EPSS 0.56%
- Veröffentlicht 04.04.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:56:22
SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-o...