Denial of Service Vulnerability in SvelteKit by Svelte
CVE-2026-82256

6.9MEDIUM

Key Information:

Vendor

Sveltejs

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-82256?

SvelteKit versions before 2.69.1 exhibit a vulnerability due to improper validation of remote form function payload sizes. This flaw allows malicious actors to send excessively large payloads, which can lead to a crash of the Node process. The application becomes vulnerable to repeated denial-of-service attacks as attackers can exploit this weakness to continuously disrupt service by causing the application to crash.

Affected Version(s)

kit 0 < 2.69.1

kit 2.69.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.