SvelteKit 在 2.69.1 版本之前未正确验证远程表单函数(remote form function)的载荷大小,攻击者可以通过发送超大载荷来使 Node 进程崩溃。反复利用该漏洞会导致应用进程反复崩溃,从而造成拒绝服务(DoS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82259 | 7.5 HIGH | SvelteKit 2.49.0 before 2.53.3 Denial of Service via form |
| CVE-2026-82260 | 7.5 HIGH | SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization |
| CVE-2026-82261 | 7.5 HIGH | SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserialization |
| CVE-2026-82258 | 5.9 MEDIUM | SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batch |
| CVE-2026-82257 | 4.3 MEDIUM | SvelteKit before 2.69.1 Prototype Pollution via File Input |
No comments yet