HIGH
GHSA-2crg-3p73-43xp
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
Quick fix
GHSA-2crg-3p73-43xp — @sveltejs/kit: upgrade to the fixed version with the command below.
npm install @sveltejs/kit@2.57.1Details
Under certain circumstances, requests could bypass the `BODY_SIZE_LIMIT` on SvelteKit applications running with `adapter-node`. This bypass does not affect body size limits at other layers of the application stack, so limits enforced in the WAF, gateway, or at the platform level are unaffected.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/sveltejs/kit/security/advisories/GHSA-2crg-3p73-43xp[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-40073[ADVISORY]
- https://github.com/sveltejs/kit/commit/3202ed6c98f9e8d86bf0c4c7ad0f2e273e5e3b95[WEB]
- https://github.com/sveltejs/kit[PACKAGE]
- https://github.com/sveltejs/kit/releases/tag/%40sveltejs%2Fkit%402.57.1[WEB]
- https://github.com/sveltejs/kit/releases/tag/@sveltejs/kit@2.57.1[WEB]