Performance Issue in Svelte Framework Versions
CVE-2026-42567
5.9MEDIUM
What is CVE-2026-42567?
An internal regular expression in the Svelte runtime can lead to significant performance degradation when processing specific HTML elements in versions 5.51.5 through 5.54.6. This situation may cause the application to hang or slow down due to exponential time complexity. The vulnerability has been addressed and patched in Svelte Framework version 5.55.7. Developers using affected versions are urged to update to ensure optimal performance and security.
Affected Version(s)
svelte >= 5.51.5, < 5.55.7
