SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly crashing the application process.
References
| Link | Resource |
|---|---|
| https://github.com/sveltejs/kit/security/advisories/GHSA-wqjv-9729-c5q2 | Vendor Advisory |
| https://www.vulncheck.com/advisories/sveltekit-before-2.69.1-denial-of-service-via-remote-form | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-28 12:16
Updated : 2026-08-31 22:22
NVD link : CVE-2026-82256
Mitre link : CVE-2026-82256
CVE.ORG link : CVE-2026-82256
JSON object : View
Products Affected
svelte
- sveltekit
CWE
CWE-400
Uncontrolled Resource Consumption
