SvelteKit (@sveltejs/kit) versions 2.49.0 through 2.52.1 contain a CPU exhaustion vulnerability in form deserialization when experimental remote functions and form features are enabled. An attacker can send malformed form data to cause the server to become unresponsive, resulting in a denial of service condition. The vulnerability requires no authentication and can be triggered remotely by any attacker capable of sending HTTP requests. The issue stems from improper handling of malformed input during deserialization, leading to excessive CPU consumption. The vulnerability has been patched in version 2.52.2. Users running affected versions with experimental remote functions and form enabled should upgrade immediately to mitigate the risk of service disruption.