Junglewise Threat Intelligence

CVE-2026-82261: SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulner

CVE-2026-82261 · Severity: high · CVSS 7.5 · Published 2026-08-28

Technologies: @sveltejs/kit (npm), SvelteKit. Vendors: npm, Svelte.

Executive brief

SvelteKit is a popular framework for building web applications in JavaScript/TypeScript. When using experimental remote functions combined with form handling, malformed form data can cause the server to consume excessive CPU and become unresponsive, effectively disabling the application. This denial-of-service vulnerability only affects applications explicitly using both experimental features together.

Technical details

This vulnerability is a denial-of-service condition triggered by insufficient validation of form file metadata in SvelteKit's deserialization logic. When the experimental.remoteFunctions and form features are both enabled, an attacker can send malformed form data that causes the server to enter an amplification/CPU exhaustion state during the devalue.parse() operation. The attack is network-reachable and requires no authentication or user interaction. An attacker can craft requests that make the server unresponsive while processing, denying service to legitimate users. The fix was released in version 2.52.2 and involves validating form file information to prevent amplification attacks.

Affected products

  • Svelte SvelteKit 2.49.0 to 2.52.1

Timeline

  • 2026-02-19: disclosed
  • 2026-02-18: patched: Fixed in version 2.52.2

References

Related threats