Junglewise Threat Intelligence

CVE-2026-22803: SvelteKit memory amplification DoS in form deserializer

CVE-2026-22803 · Severity: medium · CVSS 4 · Published 2026-01-15

Technologies: @sveltejs/kit (npm), SvelteKit. Vendors: npm, Svelte.

Executive brief

SvelteKit is a JavaScript framework for building web applications. When the experimental remote functions feature is enabled, attackers can exploit a flaw in how form data is deserialized to allocate large amounts of server memory by sending specially crafted requests and stalling the connection. This can exhaust the server's memory and cause the application to become unavailable.

Technical details

This vulnerability is a memory amplification DoS in the binary form deserializer for SvelteKit's experimental remote functions feature (application/x-sveltekit-formdata). When a form is submitted, the client encodes data in a custom format; the first 8 bytes specify the expected data length. If the request body is not yet available, SvelteKit eagerly allocates an array buffer of that size. An unauthenticated attacker can exploit this by sending the 8-byte header with a large data_length value, then stalling the connection to hold that allocation indefinitely. Repeated connections exhaust server memory, causing denial of service. The vulnerability affects SvelteKit versions 2.49.0 through 2.49.4 with experimental.remoteFunctions enabled and is fixed in version 2.49.5.

Affected products

  • SvelteJS SvelteKit 2.49.0 to 2.49.4

Timeline

  • 2026-01-15: disclosed: GHSA-j2f3-wq62-6q46 and CVE-2026-22803 published
  • 2026-01-15: patched: Fixed in @sveltejs/kit 2.49.5 and @sveltejs/adapter-node 5.5.1

References

Related threats