HIGH 8.7 NVD
CVE-2026-82260
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exh
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause excessive memory allocation, crashing the server process and resulting in denial of service. Fixed in 2.52.2.
References
- https://github.com/sveltejs/kit/security/advisories/GHSA-vrhm-gvg7-fpcf
- https://www.vulncheck.com/advisories/sveltekit-before-2.52.2-memory-exhaustion-via-remote-
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-28 via NVD.
vulnfeed aggregates 11493 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.