VYPR

kit

by SvelteKit

Source repositories

CVEs (3)

  • CVE-2026-82261HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send malformed form data to cause the server to become unresponsive while processing the…

  • CVE-2026-82260HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause excessive memory allocation,…

  • CVE-2026-66062MedAug 7, 2026
    risk 0.27cvss 5.3epss 0.00

    SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the content negotiation header parser used by SvelteKit's request handling (for headers such as Accept) uses a regular expression vulnerable to quadratic…