SvelteKit 版本从 2.49.0 到 2.53.2(在 2.53.3 中修复)在实验性远程函数(experimental remote function)中存在反序列化扩展漏洞。当应用启用了 并使用 form 函数处理 files 数组时,若未验证 或单个文件大小,攻击者可以提交相对较小的输入,使其扩展为非常大的文件数组,从而引发高开销处理并导致服务拒绝(DoS)攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82260 | 7.5 HIGH | SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization |
| CVE-2026-82261 | 7.5 HIGH | SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserialization |
| CVE-2026-82258 | 5.9 MEDIUM | SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batch |
| CVE-2026-82256 | 5.3 MEDIUM | SvelteKit before 2.69.1 Denial of Service via Remote Form |
| CVE-2026-82257 | 4.3 MEDIUM | SvelteKit before 2.69.1 Prototype Pollution via File Input |
No comments yet