Quadratic Backtracking Vulnerability in SvelteKit Framework by Svelte
CVE-2026-66062

5.3MEDIUM

Key Information:

Vendor

Sveltejs

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-66062?

A vulnerability in SvelteKit's request handling mechanism could be exploited through maliciously crafted content negotiation headers. Prior to version 2.70.2, the regular expression used for parsing headers such as Accept was susceptible to quadratic backtracking, leading to excessive CPU consumption. This might result in service degradation or interruption. The issue was addressed in version 2.70.2, reinforcing the importance of timely updates and security patches.

Affected Version(s)

kit < 2.70.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.