← Terug naar overzicht

SvelteKit (@sveltejs/kit) versions 2.49.0 through 2.52.1 contain a memory exhaustion vulnerability in remote form deserialization. The flaw is triggered when experimental remote functions (experimental.remoteFunctions) and form handling are enabled. Attackers can send malformed form data to cause excessive memory allocation, crashing the server process and resulting in a denial of service condition. The vulnerability requires no authentication and can be exploited remotely. It affects only configurations using the experimental remoteFunctions feature with forms enabled. The issue has been patched in version 2.52.2. Users are advised to upgrade immediately or disable the experimental.remoteFunctions feature as a workaround. The vulnerability is tracked as CVE-2026-82260 and has an associated GitHub Security Advisory GHSA-vrhm-gvg7-fpcf.

Affected products

  • SvelteKit (@sveltejs/kit) >=2.49.0 <=2.52.1

Related CVE's

  • CVE-2026-82260

Categories

  • Supply Chain & Dependencies
  • Web Technologies