SvelteKit 从 2.38.0 到 2.60.1 之前的版本中, 存在一个竞态条件(race condition),使得来自不同用户的并发请求可能会在同一个请求上下文中合并。攻击者可以利用特定的时序条件,访问其他用户并发请求中的敏感数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82259 | 7.5 HIGH | SvelteKit 2.49.0 before 2.53.3 Denial of Service via form |
| CVE-2026-82260 | 7.5 HIGH | SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization |
| CVE-2026-82261 | 7.5 HIGH | SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserialization |
| CVE-2026-82256 | 5.3 MEDIUM | SvelteKit before 2.69.1 Denial of Service via Remote Form |
| CVE-2026-82257 | 4.3 MEDIUM | SvelteKit before 2.69.1 Prototype Pollution via File Input |
No comments yet