{"schema_version":1,"title":"Svelte vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 22 vulnerabilities in Svelte: 0 in the last 7 days and 10 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-92708, was published on 18 September 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/svelte","json_url":"https://junglewise.ai/threats/vendors/svelte.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/svelte","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":6,"all_time":22,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":7,"last_90_days":10,"last_365_days":16},"latest":[{"cve":"CVE-2026-92708","cvss":7.5,"epss":0.0057,"slug":"cve-2026-92708-svelte-devalue-is-a-javascript-library-that-serializes-values","title":"Svelte devalue memory disclosure in Node Buffer serialization","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:30.15+00:00","url":"https://junglewise.ai/threats/cve-2026-92708-svelte-devalue-is-a-javascript-library-that-serializes-values"},{"cve":"CVE-2026-82261","cvss":7.5,"epss":0.0049,"slug":"cve-2026-82261-sveltekit-cpu-exhaustion-in-remote-form-deserialization","title":"SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulner","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:39.25+00:00","url":"https://junglewise.ai/threats/cve-2026-82261-sveltekit-cpu-exhaustion-in-remote-form-deserialization"},{"cve":"CVE-2026-82260","cvss":7.5,"epss":0.0049,"slug":"cve-2026-82260-sveltekit-memory-exhaustion-in-remote-form-deserialization","title":"SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:39.1+00:00","url":"https://junglewise.ai/threats/cve-2026-82260-sveltekit-memory-exhaustion-in-remote-form-deserialization"},{"cve":"CVE-2026-82259","cvss":7.5,"epss":0.0053,"slug":"cve-2026-82259-sveltekit-deserialization-expansion-in-form-remote-function","title":"SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote fu","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:38.953+00:00","url":"https://junglewise.ai/threats/cve-2026-82259-sveltekit-deserialization-expansion-in-form-remote-function"},{"cve":"CVE-2026-82258","cvss":4.8,"epss":0.0024,"slug":"cve-2026-82258-sveltejs-kit-query-batch-cross-talk-vulnerability","title":"SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.77+00:00","url":"https://junglewise.ai/threats/cve-2026-82258-sveltejs-kit-query-batch-cross-talk-vulnerability"},{"cve":"CVE-2026-82257","cvss":4.3,"epss":0.0036,"slug":"cve-2026-82257-sveltekit-prototype-pollution-in-file-input-deletion","title":"SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arb","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.607+00:00","url":"https://junglewise.ai/threats/cve-2026-82257-sveltekit-prototype-pollution-in-file-input-deletion"},{"cve":"CVE-2026-82256","cvss":5.3,"epss":0.0042,"slug":"cve-2026-82256-sveltekit-unhandled-promise-rejection-in-form-payload-handling","title":"SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sendi","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.457+00:00","url":"https://junglewise.ai/threats/cve-2026-82256-sveltekit-unhandled-promise-rejection-in-form-payload-handling"},{"cve":"CVE-2026-66062","cvss":5.3,"epss":0.0051,"slug":"cve-2026-66062-svelte-sveltekit-redos-in-accept-header-content-negotiation","title":"Svelte SvelteKit ReDoS in Accept header content negotiation","severity":"medium","exploited":false,"published_at":"2026-08-07T16:50:02+00:00","url":"https://junglewise.ai/threats/cve-2026-66062-svelte-sveltekit-redos-in-accept-header-content-negotiation"},{"cvss":4.3,"slug":"sveltekit-prototype-pollution-in-remote-function-forms-d7c09314","title":"SvelteKit prototype pollution in remote-function forms","severity":"medium","exploited":false,"published_at":"2026-07-24T15:58:05+00:00","url":"https://junglewise.ai/threats/sveltekit-prototype-pollution-in-remote-function-forms-d7c09314"},{"cvss":5.3,"slug":"svelte-sveltekit-denial-of-service-via-large-form-payloads-2ac113a1","title":"Svelte SvelteKit Denial of Service via large form payloads","severity":"medium","exploited":false,"published_at":"2026-07-24T15:50:40+00:00","url":"https://junglewise.ai/threats/svelte-sveltekit-denial-of-service-via-large-form-payloads-2ac113a1"},{"cvss":5.9,"slug":"svelte-sveltekit-cross-user-data-disclosure-in-query-batch-72bcef47","title":"Svelte SvelteKit cross-user data disclosure in query.batch","severity":"medium","exploited":false,"published_at":"2026-05-21T17:59:05+00:00","url":"https://junglewise.ai/threats/svelte-sveltekit-cross-user-data-disclosure-in-query-batch-72bcef47"},{"cve":"CVE-2026-40074","cvss":7.5,"epss":0.0061,"slug":"cve-2026-40074-svelte-sveltekit-denial-of-service-in-redirect-function","title":"Svelte SvelteKit denial of service in redirect function","severity":"high","exploited":false,"published_at":"2026-04-10T17:17:12.513+00:00","url":"https://junglewise.ai/threats/cve-2026-40074-svelte-sveltekit-denial-of-service-in-redirect-function"},{"cve":"CVE-2026-40073","cvss":7.5,"epss":0.0096,"slug":"cve-2026-40073-svelte-sveltekit-body-size-limit-bypass-in-adapter-node","title":"Svelte SvelteKit body size limit bypass in adapter-node","severity":"high","exploited":false,"published_at":"2026-04-10T17:17:12.357+00:00","url":"https://junglewise.ai/threats/cve-2026-40073-svelte-sveltekit-body-size-limit-bypass-in-adapter-node"},{"cve":"CVE-2026-27118","cvss":4,"epss":0.0022,"slug":"cve-2026-27118-svelte-adapter-vercel-cache-poisoning-via-isr-query-parameter","title":"Svelte adapter-vercel cache poisoning via ISR query parameter","severity":"medium","exploited":false,"published_at":"2026-02-19T15:18:02+00:00","url":"https://junglewise.ai/threats/cve-2026-27118-svelte-adapter-vercel-cache-poisoning-via-isr-query-parameter"},{"cve":"CVE-2026-22803","cvss":4,"epss":0.006,"slug":"cve-2026-22803-sveltekit-memory-amplification-dos-in-form-deserializer","title":"SvelteKit memory amplification DoS in form deserializer","severity":"medium","exploited":false,"published_at":"2026-01-15T18:10:52+00:00","url":"https://junglewise.ai/threats/cve-2026-22803-sveltekit-memory-amplification-dos-in-form-deserializer"},{"cve":"CVE-2025-67647","cvss":4,"epss":0.0053,"slug":"cve-2025-67647-sveltekit-denial-of-service-and-ssrf-in-prerendering","title":"SvelteKit denial of service and SSRF in prerendering","severity":"medium","exploited":false,"published_at":"2026-01-15T18:09:59+00:00","url":"https://junglewise.ai/threats/cve-2025-67647-sveltekit-denial-of-service-and-ssrf-in-prerendering"},{"cve":"CVE-2025-32388","cvss":3.1,"epss":0.003,"slug":"cve-2025-32388-sveltekit-cross-site-scripting-via-tracked-search-parameters","title":"SvelteKit cross-site scripting via tracked search parameters","severity":"low","exploited":false,"published_at":"2025-04-14T19:10:42+00:00","url":"https://junglewise.ai/threats/cve-2025-32388-sveltekit-cross-site-scripting-via-tracked-search-parameters"},{"cve":"CVE-2024-53261","cvss":3.1,"epss":0.0033,"slug":"cve-2024-53261-sveltejs-kit-cross-site-scripting-in-dev-mode-404-page","title":"SvelteJS Kit cross-site scripting in dev mode 404 page","severity":"low","exploited":false,"published_at":"2024-11-25T15:33:19+00:00","url":"https://junglewise.ai/threats/cve-2024-53261-sveltejs-kit-cross-site-scripting-in-dev-mode-404-page"},{"cve":"CVE-2024-53262","cvss":3.1,"epss":0.0048,"slug":"cve-2024-53262-sveltejs-kit-unescaped-error-message-xss-on-error-page","title":"SvelteJS Kit unescaped error message XSS on error page","severity":"low","exploited":false,"published_at":"2024-11-25T15:32:45+00:00","url":"https://junglewise.ai/threats/cve-2024-53262-sveltejs-kit-unescaped-error-message-xss-on-error-page"},{"cve":"CVE-2024-23641","cvss":3.1,"epss":0.0076,"slug":"cve-2024-23641-sveltekit-denial-of-service-via-get-head-requests-with-body","title":"SvelteKit denial of service via GET/HEAD requests with body","severity":"low","exploited":false,"published_at":"2024-01-24T14:22:22+00:00","url":"https://junglewise.ai/threats/cve-2024-23641-sveltekit-denial-of-service-via-get-head-requests-with-body"},{"cve":"CVE-2023-29008","cvss":3.1,"epss":0.0037,"slug":"cve-2023-29008-sveltekit-insufficient-csrf-protection-in-cors-requests","title":"SvelteKit insufficient CSRF protection in CORS requests","severity":"low","exploited":false,"published_at":"2023-04-07T19:23:31+00:00","url":"https://junglewise.ai/threats/cve-2023-29008-sveltekit-insufficient-csrf-protection-in-cors-requests"},{"cve":"CVE-2023-29003","cvss":3.1,"epss":0.0056,"slug":"cve-2023-29003-sveltekit-insufficient-cross-site-request-forgery-protection","title":"SvelteKit insufficient cross-site request forgery protection","severity":"low","exploited":false,"published_at":"2023-04-04T21:20:47+00:00","url":"https://junglewise.ai/threats/cve-2023-29003-sveltekit-insufficient-cross-site-request-forgery-protection"}],"vendor":{"hub":true,"name":"Svelte","slug":"svelte","homepage":"https://svelte.dev/","description":"Svelte is a community-driven project that provides tools for building user interfaces.","url":"https://junglewise.ai/threats/vendors/svelte"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-40073","cvss":7.5,"epss":0.0096,"slug":"cve-2026-40073-svelte-sveltekit-body-size-limit-bypass-in-adapter-node","title":"Svelte SvelteKit body size limit bypass in adapter-node","severity":"high","exploited":false,"published_at":"2026-04-10T17:17:12.357+00:00","url":"https://junglewise.ai/threats/cve-2026-40073-svelte-sveltekit-body-size-limit-bypass-in-adapter-node"},{"cve":"CVE-2026-40074","cvss":7.5,"epss":0.0061,"slug":"cve-2026-40074-svelte-sveltekit-denial-of-service-in-redirect-function","title":"Svelte SvelteKit denial of service in redirect function","severity":"high","exploited":false,"published_at":"2026-04-10T17:17:12.513+00:00","url":"https://junglewise.ai/threats/cve-2026-40074-svelte-sveltekit-denial-of-service-in-redirect-function"},{"cve":"CVE-2026-92708","cvss":7.5,"epss":0.0057,"slug":"cve-2026-92708-svelte-devalue-is-a-javascript-library-that-serializes-values","title":"Svelte devalue memory disclosure in Node Buffer serialization","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:30.15+00:00","url":"https://junglewise.ai/threats/cve-2026-92708-svelte-devalue-is-a-javascript-library-that-serializes-values"},{"cve":"CVE-2026-82259","cvss":7.5,"epss":0.0053,"slug":"cve-2026-82259-sveltekit-deserialization-expansion-in-form-remote-function","title":"SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote fu","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:38.953+00:00","url":"https://junglewise.ai/threats/cve-2026-82259-sveltekit-deserialization-expansion-in-form-remote-function"},{"cve":"CVE-2026-82261","cvss":7.5,"epss":0.0049,"slug":"cve-2026-82261-sveltekit-cpu-exhaustion-in-remote-form-deserialization","title":"SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulner","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:39.25+00:00","url":"https://junglewise.ai/threats/cve-2026-82261-sveltekit-cpu-exhaustion-in-remote-form-deserialization"},{"cve":"CVE-2026-82260","cvss":7.5,"epss":0.0049,"slug":"cve-2026-82260-sveltekit-memory-exhaustion-in-remote-form-deserialization","title":"SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:39.1+00:00","url":"https://junglewise.ai/threats/cve-2026-82260-sveltekit-memory-exhaustion-in-remote-form-deserialization"},{"cvss":5.9,"slug":"svelte-sveltekit-cross-user-data-disclosure-in-query-batch-72bcef47","title":"Svelte SvelteKit cross-user data disclosure in query.batch","severity":"medium","exploited":false,"published_at":"2026-05-21T17:59:05+00:00","url":"https://junglewise.ai/threats/svelte-sveltekit-cross-user-data-disclosure-in-query-batch-72bcef47"},{"cve":"CVE-2026-66062","cvss":5.3,"epss":0.0051,"slug":"cve-2026-66062-svelte-sveltekit-redos-in-accept-header-content-negotiation","title":"Svelte SvelteKit ReDoS in Accept header content negotiation","severity":"medium","exploited":false,"published_at":"2026-08-07T16:50:02+00:00","url":"https://junglewise.ai/threats/cve-2026-66062-svelte-sveltekit-redos-in-accept-header-content-negotiation"},{"cve":"CVE-2026-82256","cvss":5.3,"epss":0.0042,"slug":"cve-2026-82256-sveltekit-unhandled-promise-rejection-in-form-payload-handling","title":"SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sendi","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.457+00:00","url":"https://junglewise.ai/threats/cve-2026-82256-sveltekit-unhandled-promise-rejection-in-form-payload-handling"},{"cvss":5.3,"slug":"svelte-sveltekit-denial-of-service-via-large-form-payloads-2ac113a1","title":"Svelte SvelteKit Denial of Service via large form payloads","severity":"medium","exploited":false,"published_at":"2026-07-24T15:50:40+00:00","url":"https://junglewise.ai/threats/svelte-sveltekit-denial-of-service-via-large-form-payloads-2ac113a1"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"SvelteKit","slug":"sveltekit","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/sveltekit"},{"name":"Svelte Kit","slug":"kit","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/kit"}]}