Executive brief
Svelte is a popular framework used to build web user interfaces. A performance flaw in how it handles dynamic HTML elements could allow an attacker to crash a website or make it unresponsive by providing extremely long or complex tag names. This could lead to a service outage for users of the affected application.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Svelte runtime within the `<svelte:element>` tag validation logic. The internal regular expression used to validate the `this={tag}` attribute can exhibit exponential backtracking when processing unconstrained, specially crafted input strings. An attacker who can control the tag name passed to this component can cause the JavaScript execution thread to hang, leading to a denial of service. This vulnerability is mitigated if the application restricts tag names to a known-safe list or enforces strict length limits. The issue is fixed in Svelte version 5.55.7.
Affected products
- sveltejs svelte >= 5.51.5, <= 5.55.6
Timeline
- 2026-05-14: disclosed
- 2026-05-14: advisory
- 2026-05-14: patched: Fixed in version 5.55.7