High severity7.5NVD Advisory· Published Aug 28, 2026
CVE-2026-82260
CVE-2026-82260
Description
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause excessive memory allocation, crashing the server process and resulting in denial of service. Fixed in 2.52.2.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.