漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SvelteKit has a memory amplification DoS in Remote Functions binary form deserializer
Vulnerability Description
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4, the experimental form remote function uses a binary data format containing a representation of submitted form data. A specially-crafted payload can cause the server to allocate a large amount of memory, causing DoS via memory exhaustion. This vulnerability is fixed in 2.49.5.
CVSS Information
N/A
Vulnerability Type
未经控制的内存分配
Vulnerability Title
SvelteKit 安全漏洞
Vulnerability Description
SvelteKit是Svelte开源的一套Web 开发框架。 SvelteKit 2.49.0版本至2.49.4版本存在安全漏洞,该漏洞源于实验性表单远程函数处理特制有效载荷不当,可能导致内存耗尽拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A