SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause excessive memory allocation, crashing the server process and resulting in denial of service. Fixed in 2.52.2.
References
| Link | Resource |
|---|---|
| https://github.com/sveltejs/kit/security/advisories/GHSA-vrhm-gvg7-fpcf | Vendor Advisory |
| https://www.vulncheck.com/advisories/sveltekit-before-2.52.2-memory-exhaustion-via-remote-form-deserialization | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-28 12:16
Updated : 2026-08-31 17:08
NVD link : CVE-2026-82260
Mitre link : CVE-2026-82260
CVE.ORG link : CVE-2026-82260
JSON object : View
Products Affected
svelte
- sveltekit
CWE
CWE-400
Uncontrolled Resource Consumption
