Performance Issue in Svelte Framework Versions
CVE-2026-42567

5.9MEDIUM

Key Information:

Vendor

Sveltejs

Status
Vendor
CVE Published:
9 June 2026

What is CVE-2026-42567?

An internal regular expression in the Svelte runtime can lead to significant performance degradation when processing specific HTML elements in versions 5.51.5 through 5.54.6. This situation may cause the application to hang or slow down due to exponential time complexity. The vulnerability has been addressed and patched in Svelte Framework version 5.55.7. Developers using affected versions are urged to update to ensure optimal performance and security.

Affected Version(s)

svelte >= 5.51.5, < 5.55.7

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.