← Terug naar overzicht

SvelteKit (@sveltejs/kit) versions 2.49.0 through 2.52.1 contain a memory exhaustion vulnerability in remote form deserialization. The flaw is triggered when the experimental.remoteFunctions feature is enabled along with form support. Malformed form data can cause excessive memory allocation, ultimately crashing the server process and resulting in denial of service. The vulnerability is exploitable remotely by sending specially crafted malformed form data to the affected server. No authentication appears to be required to trigger the issue. The vulnerability has been fixed in SvelteKit version 2.52.2. Users are advised to upgrade immediately. A GitHub Security Advisory (GHSA-vrhm-gvg7-fpcf) and VulnCheck advisory have been published alongside the NVD entry.

Affected products

  • SvelteKit (@sveltejs/kit) >=2.49.0 <=2.52.1

Related CVE's

  • CVE-2026-82260

Categories

  • Supply Chain & Dependencies
  • Web Technologies