PT-2026-31989 · Sveltekit+1 · Sveltekit+1
CVE-2026-40073
·
Published
2026-04-10
·
Updated
2026-04-10
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SvelteKit versions prior to 2.57.1
Description
SvelteKit, a framework for building web applications, had a potential issue where requests could bypass the
BODY SIZE LIMIT when using the adapter-node. This bypass did not impact body size limits enforced by other security measures like Web Application Firewalls (WAFs) or platform-level restrictions.Recommendations
Update to SvelteKit version 2.57.1 or later.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sveltekit
Adapter-Node