SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause excessive memory allocation, crashing the server process and resulting in denial of service. Fixed in 2.52.2.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause excessive memory allocation, crashing the server process and resulting in denial of service. Fixed in 2.52.2. | |
| Title | SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization | |
| First Time appeared |
Svelte
Svelte kit |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:svelte:kit:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Svelte
Svelte kit |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-28T10:49:43.651Z
Updated: 2026-08-28T15:52:30.481Z
Reserved: 2026-08-28T10:39:30.356Z
Link: CVE-2026-82260
No data.
Status : Undergoing Analysis
Published: 2026-08-28T12:16:39.100
Modified: 2026-08-28T20:20:16.520
Link: CVE-2026-82260
No data.