PT-2026-83112 · Sveltekit · Sveltekit

·

CVE-2026-82260

·

Published

2026-02-19

·

Updated

2026-08-28

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SvelteKit (@sveltejs/kit) versions 2.49.0 through 2.52.1
Description A memory exhaustion issue exists during remote form deserialization when experimental remote functions (experimental.remoteFunctions) and form features are enabled. An attacker can send malformed form data to trigger excessive memory allocation, which crashes the server process and leads to a denial of service.
Recommendations Update SvelteKit (@sveltejs/kit) to version 2.52.2. As a temporary mitigation, disable the experimental.remoteFunctions feature.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82260
GHSA-VRHM-GVG7-FPCF

Affected Products

Sveltekit