Medium severityNVD Advisory· Published Aug 28, 2026
CVE-2026-82258
CVE-2026-82258
Description
SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploit specific timing conditions to access sensitive data from other users' concurrent requests.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.