CVE-2026-82260

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause excessive memory allocation, crashing the server process and resulting in denial of service. Fixed in 2.52.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:svelte:sveltekit:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-08-28 12:16

Updated : 2026-08-31 17:08


NVD link : CVE-2026-82260

Mitre link : CVE-2026-82260

CVE.ORG link : CVE-2026-82260


JSON object : View

Products Affected

svelte

  • sveltekit
CWE
CWE-400

Uncontrolled Resource Consumption