SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly crashing the application process.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly crashing the application process. | |
| Title | SvelteKit before 2.69.1 Denial of Service via Remote Form | |
| First Time appeared |
Svelte
Svelte kit |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:svelte:kit:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Svelte
Svelte kit |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-28T10:49:40.634Z
Updated: 2026-08-28T14:41:47.444Z
Reserved: 2026-08-28T10:39:30.355Z
Link: CVE-2026-82256
Updated: 2026-08-28T14:41:32.651Z
Status : Awaiting Analysis
Published: 2026-08-28T12:16:38.457
Modified: 2026-08-28T18:56:34.447
Link: CVE-2026-82256
No data.