Quadratic Backtracking Vulnerability in SvelteKit Framework by Svelte
CVE-2026-66062
5.3MEDIUM
What is CVE-2026-66062?
A vulnerability in SvelteKit's request handling mechanism could be exploited through maliciously crafted content negotiation headers. Prior to version 2.70.2, the regular expression used for parsing headers such as Accept was susceptible to quadratic backtracking, leading to excessive CPU consumption. This might result in service degradation or interruption. The issue was addressed in version 2.70.2, reinforcing the importance of timely updates and security patches.
Affected Version(s)
kit < 2.70.2
