PT-2026-69081 · Sveltekit · Sveltekit

CVE-2026-66062

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions SvelteKit versions prior to 2.70.2
Description The content negotiation header parser used in request handling is susceptible to a regular expression vulnerability known as quadratic backtracking. This occurs when a specifically crafted value in the Accept header causes the system to perform an excessive number of computations, leading to high CPU consumption. This can result in a denial of service (DoS), although the impact is often mitigated by default header length limits on many platforms.
Recommendations Update to version 2.70.2.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66062
GHSA-29G2-3RMR-QM68

Affected Products

Sveltekit