SvelteKit (@sveltejs/kit) versions 2.49.0 through 2.52.1 contain a CPU exhaustion vulnerability in form deserialization when experimental remote functions and form features are enabled. An attacker can send malformed form data to cause the server to become unresponsive, resulting in a denial of service condition. The vulnerability affects only configurations with both experimental remote functions and form handling enabled. No authentication is required to exploit this vulnerability, making it accessible to unauthenticated attackers. The issue has been patched in version 2.52.2 of SvelteKit. Users are advised to upgrade immediately to mitigate the risk of server unavailability.