Junglewise Threat Intelligence

CVE-2026-82260: SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled

CVE-2026-82260 · Severity: high · CVSS 7.5 · Published 2026-08-28

Technologies: @sveltejs/kit (npm), SvelteKit. Vendors: npm, Svelte.

Executive brief

SvelteKit is a web development framework used to build server-side rendered applications. When the experimental remote functions feature is enabled alongside form handling, attackers can send malformed form data to crash the application server through excessive memory allocation, causing a denial-of-service outage.

Technical details

This vulnerability is a memory exhaustion / denial-of-service issue (CWE-770) in SvelteKit's binary form deserialization logic. The vulnerability affects versions 2.49.0 through 2.52.1 when both experimental.remoteFunctions and form handling are enabled. An unauthenticated attacker on the network can send crafted form data that triggers excessive memory allocation during deserialization, crashing the server process without requiring authentication or user interaction. The fix, released in version 2.52.2, implements stricter parsing of the file offset table during binary form deserialization.

Affected products

  • Svelte @sveltejs/kit 2.49.0 through 2.52.1

Timeline

  • 2026-02-19: disclosed: GHSA-vrhm-gvg7-fpcf and CVE-2026-82260 published
  • 2026-02-18: patched: Fix merged (commit f47c01bd) targeting version 2.52.2

References

Related threats