{"schema_version":1,"title":"SvelteKit vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 17 vulnerabilities in SvelteKit: 0 in the last 7 days and 9 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-82261, was published on 28 August 2026.","url":"https://junglewise.ai/threats/technologies/sveltekit","json_url":"https://junglewise.ai/threats/technologies/sveltekit.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/sveltekit","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":5,"all_time":17,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":9,"last_365_days":13},"latest":[{"cve":"CVE-2026-82261","cvss":7.5,"epss":0.0049,"slug":"cve-2026-82261-sveltekit-cpu-exhaustion-in-remote-form-deserialization","title":"SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulner","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:39.25+00:00","url":"https://junglewise.ai/threats/cve-2026-82261-sveltekit-cpu-exhaustion-in-remote-form-deserialization"},{"cve":"CVE-2026-82260","cvss":7.5,"epss":0.0049,"slug":"cve-2026-82260-sveltekit-memory-exhaustion-in-remote-form-deserialization","title":"SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:39.1+00:00","url":"https://junglewise.ai/threats/cve-2026-82260-sveltekit-memory-exhaustion-in-remote-form-deserialization"},{"cve":"CVE-2026-82259","cvss":7.5,"epss":0.0053,"slug":"cve-2026-82259-sveltekit-deserialization-expansion-in-form-remote-function","title":"SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote fu","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:38.953+00:00","url":"https://junglewise.ai/threats/cve-2026-82259-sveltekit-deserialization-expansion-in-form-remote-function"},{"cve":"CVE-2026-82258","cvss":4.8,"epss":0.0024,"slug":"cve-2026-82258-sveltejs-kit-query-batch-cross-talk-vulnerability","title":"SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.77+00:00","url":"https://junglewise.ai/threats/cve-2026-82258-sveltejs-kit-query-batch-cross-talk-vulnerability"},{"cve":"CVE-2026-82257","cvss":4.3,"epss":0.0036,"slug":"cve-2026-82257-sveltekit-prototype-pollution-in-file-input-deletion","title":"SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arb","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.607+00:00","url":"https://junglewise.ai/threats/cve-2026-82257-sveltekit-prototype-pollution-in-file-input-deletion"},{"cve":"CVE-2026-82256","cvss":5.3,"epss":0.0042,"slug":"cve-2026-82256-sveltekit-unhandled-promise-rejection-in-form-payload-handling","title":"SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sendi","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.457+00:00","url":"https://junglewise.ai/threats/cve-2026-82256-sveltekit-unhandled-promise-rejection-in-form-payload-handling"},{"cve":"CVE-2026-66062","cvss":5.3,"epss":0.0051,"slug":"cve-2026-66062-svelte-sveltekit-redos-in-accept-header-content-negotiation","title":"Svelte SvelteKit ReDoS in Accept header content negotiation","severity":"medium","exploited":false,"published_at":"2026-08-07T16:50:02+00:00","url":"https://junglewise.ai/threats/cve-2026-66062-svelte-sveltekit-redos-in-accept-header-content-negotiation"},{"cvss":4.3,"slug":"sveltekit-prototype-pollution-in-remote-function-forms-d7c09314","title":"SvelteKit prototype pollution in remote-function forms","severity":"medium","exploited":false,"published_at":"2026-07-24T15:58:05+00:00","url":"https://junglewise.ai/threats/sveltekit-prototype-pollution-in-remote-function-forms-d7c09314"},{"cvss":5.3,"slug":"svelte-sveltekit-denial-of-service-via-large-form-payloads-2ac113a1","title":"Svelte SvelteKit Denial of Service via large form payloads","severity":"medium","exploited":false,"published_at":"2026-07-24T15:50:40+00:00","url":"https://junglewise.ai/threats/svelte-sveltekit-denial-of-service-via-large-form-payloads-2ac113a1"},{"cve":"CVE-2026-40074","cvss":7.5,"epss":0.0061,"slug":"cve-2026-40074-svelte-sveltekit-denial-of-service-in-redirect-function","title":"Svelte SvelteKit denial of service in redirect function","severity":"high","exploited":false,"published_at":"2026-04-10T17:17:12.513+00:00","url":"https://junglewise.ai/threats/cve-2026-40074-svelte-sveltekit-denial-of-service-in-redirect-function"},{"cve":"CVE-2026-40073","cvss":7.5,"epss":0.0096,"slug":"cve-2026-40073-svelte-sveltekit-body-size-limit-bypass-in-adapter-node","title":"Svelte SvelteKit body size limit bypass in adapter-node","severity":"high","exploited":false,"published_at":"2026-04-10T17:17:12.357+00:00","url":"https://junglewise.ai/threats/cve-2026-40073-svelte-sveltekit-body-size-limit-bypass-in-adapter-node"},{"cve":"CVE-2026-22803","cvss":4,"epss":0.006,"slug":"cve-2026-22803-sveltekit-memory-amplification-dos-in-form-deserializer","title":"SvelteKit memory amplification DoS in form deserializer","severity":"medium","exploited":false,"published_at":"2026-01-15T18:10:52+00:00","url":"https://junglewise.ai/threats/cve-2026-22803-sveltekit-memory-amplification-dos-in-form-deserializer"},{"cve":"CVE-2025-67647","cvss":4,"epss":0.0053,"slug":"cve-2025-67647-sveltekit-denial-of-service-and-ssrf-in-prerendering","title":"SvelteKit denial of service and SSRF in prerendering","severity":"medium","exploited":false,"published_at":"2026-01-15T18:09:59+00:00","url":"https://junglewise.ai/threats/cve-2025-67647-sveltekit-denial-of-service-and-ssrf-in-prerendering"},{"cve":"CVE-2025-32388","cvss":3.1,"epss":0.003,"slug":"cve-2025-32388-sveltekit-cross-site-scripting-via-tracked-search-parameters","title":"SvelteKit cross-site scripting via tracked search parameters","severity":"low","exploited":false,"published_at":"2025-04-14T19:10:42+00:00","url":"https://junglewise.ai/threats/cve-2025-32388-sveltekit-cross-site-scripting-via-tracked-search-parameters"},{"cve":"CVE-2024-23641","cvss":3.1,"epss":0.0076,"slug":"cve-2024-23641-sveltekit-denial-of-service-via-get-head-requests-with-body","title":"SvelteKit denial of service via GET/HEAD requests with body","severity":"low","exploited":false,"published_at":"2024-01-24T14:22:22+00:00","url":"https://junglewise.ai/threats/cve-2024-23641-sveltekit-denial-of-service-via-get-head-requests-with-body"},{"cve":"CVE-2023-29008","cvss":3.1,"epss":0.0037,"slug":"cve-2023-29008-sveltekit-insufficient-csrf-protection-in-cors-requests","title":"SvelteKit insufficient CSRF protection in CORS requests","severity":"low","exploited":false,"published_at":"2023-04-07T19:23:31+00:00","url":"https://junglewise.ai/threats/cve-2023-29008-sveltekit-insufficient-csrf-protection-in-cors-requests"},{"cve":"CVE-2023-29003","cvss":3.1,"epss":0.0056,"slug":"cve-2023-29003-sveltekit-insufficient-cross-site-request-forgery-protection","title":"SvelteKit insufficient cross-site request forgery protection","severity":"low","exploited":false,"published_at":"2023-04-04T21:20:47+00:00","url":"https://junglewise.ai/threats/cve-2023-29003-sveltekit-insufficient-cross-site-request-forgery-protection"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Svelte Kit","slug":"kit","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/kit"}],"technology":{"hub":true,"name":"SvelteKit","slug":"sveltekit","vendor":{"name":"Svelte","slug":"svelte","url":"https://junglewise.ai/threats/vendors/svelte"},"aliases":[],"category":"framework","url":"https://junglewise.ai/threats/technologies/sveltekit"},"most_severe":[{"cve":"CVE-2026-40073","cvss":7.5,"epss":0.0096,"slug":"cve-2026-40073-svelte-sveltekit-body-size-limit-bypass-in-adapter-node","title":"Svelte SvelteKit body size limit bypass in adapter-node","severity":"high","exploited":false,"published_at":"2026-04-10T17:17:12.357+00:00","url":"https://junglewise.ai/threats/cve-2026-40073-svelte-sveltekit-body-size-limit-bypass-in-adapter-node"},{"cve":"CVE-2026-40074","cvss":7.5,"epss":0.0061,"slug":"cve-2026-40074-svelte-sveltekit-denial-of-service-in-redirect-function","title":"Svelte SvelteKit denial of service in redirect function","severity":"high","exploited":false,"published_at":"2026-04-10T17:17:12.513+00:00","url":"https://junglewise.ai/threats/cve-2026-40074-svelte-sveltekit-denial-of-service-in-redirect-function"},{"cve":"CVE-2026-82259","cvss":7.5,"epss":0.0053,"slug":"cve-2026-82259-sveltekit-deserialization-expansion-in-form-remote-function","title":"SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote fu","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:38.953+00:00","url":"https://junglewise.ai/threats/cve-2026-82259-sveltekit-deserialization-expansion-in-form-remote-function"},{"cve":"CVE-2026-82261","cvss":7.5,"epss":0.0049,"slug":"cve-2026-82261-sveltekit-cpu-exhaustion-in-remote-form-deserialization","title":"SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulner","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:39.25+00:00","url":"https://junglewise.ai/threats/cve-2026-82261-sveltekit-cpu-exhaustion-in-remote-form-deserialization"},{"cve":"CVE-2026-82260","cvss":7.5,"epss":0.0049,"slug":"cve-2026-82260-sveltekit-memory-exhaustion-in-remote-form-deserialization","title":"SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:39.1+00:00","url":"https://junglewise.ai/threats/cve-2026-82260-sveltekit-memory-exhaustion-in-remote-form-deserialization"},{"cve":"CVE-2026-66062","cvss":5.3,"epss":0.0051,"slug":"cve-2026-66062-svelte-sveltekit-redos-in-accept-header-content-negotiation","title":"Svelte SvelteKit ReDoS in Accept header content negotiation","severity":"medium","exploited":false,"published_at":"2026-08-07T16:50:02+00:00","url":"https://junglewise.ai/threats/cve-2026-66062-svelte-sveltekit-redos-in-accept-header-content-negotiation"},{"cve":"CVE-2026-82256","cvss":5.3,"epss":0.0042,"slug":"cve-2026-82256-sveltekit-unhandled-promise-rejection-in-form-payload-handling","title":"SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sendi","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.457+00:00","url":"https://junglewise.ai/threats/cve-2026-82256-sveltekit-unhandled-promise-rejection-in-form-payload-handling"},{"cvss":5.3,"slug":"svelte-sveltekit-denial-of-service-via-large-form-payloads-2ac113a1","title":"Svelte SvelteKit Denial of Service via large form payloads","severity":"medium","exploited":false,"published_at":"2026-07-24T15:50:40+00:00","url":"https://junglewise.ai/threats/svelte-sveltekit-denial-of-service-via-large-form-payloads-2ac113a1"},{"cve":"CVE-2026-82258","cvss":4.8,"epss":0.0024,"slug":"cve-2026-82258-sveltejs-kit-query-batch-cross-talk-vulnerability","title":"SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.77+00:00","url":"https://junglewise.ai/threats/cve-2026-82258-sveltejs-kit-query-batch-cross-talk-vulnerability"},{"cve":"CVE-2026-82257","cvss":4.3,"epss":0.0036,"slug":"cve-2026-82257-sveltekit-prototype-pollution-in-file-input-deletion","title":"SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arb","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.607+00:00","url":"https://junglewise.ai/threats/cve-2026-82257-sveltekit-prototype-pollution-in-file-input-deletion"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}