SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
Modified: 8/7/2026
package
pkg:npm/%40sveltejs/kit
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
Modified: 8/7/2026
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
Modified: 4/10/2026
@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
Modified: 4/10/2026
SvelteKit vulnerable to Cross-Site Request Forgery
Modified: 9/10/2026
@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params
Modified: 4/16/2025
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
Modified: 8/29/2026
CPU exhaustion in SvelteKit remote form deserialization (experimental only)
Modified: 9/2/2026
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
Modified: 8/29/2026
Sending a GET or HEAD request with a body crashes SvelteKit
Modified: 9/10/2026
SvelteKit framework has Insufficient CSRF protection for CORS requests
Modified: 11/8/2023
@sveltejs/kit: `query.batch` cross-talk
Modified: 9/10/2026
@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)
Modified: 2/3/2026
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
Modified: 2/3/2026
@sveltejs/kit has unescaped error message included on error page
Modified: 11/25/2024
@sveltejs/kit vulnerable to XSS on dev mode 404 page
Modified: 1/22/2025
Memory exhaustion in SvelteKit remote form deserialization (experimental only)
Modified: 9/2/2026
SvelteKit: Big remote form function payloads can cause Node process to crash
Modified: 8/29/2026