← Terug naar overzicht

SvelteKit (@sveltejs/kit) versions 2.49.0 through 2.52.1 contain a CPU exhaustion vulnerability in form deserialization when experimental remote functions and form features are enabled. An attacker can send malformed form data to cause the server to become unresponsive, resulting in a denial of service condition. The vulnerability only affects installations with the experimental remote functions and form features explicitly enabled. No authentication is required to exploit this vulnerability, as the malformed form data can be sent by any remote attacker. The issue has been patched in version 2.52.2. Users are advised to upgrade immediately or disable the experimental remote functions and form features as a workaround.

Affected products

  • SvelteKit (@sveltejs/kit) >=2.49.0 <=2.52.1

Related CVE's

  • CVE-2026-82261

Categories

  • Supply Chain & Dependencies
  • Web Technologies