Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82259— SvelteKit 2.49.0 before 2.53.3 Denial of Service via form

Quick assessment

Affected
sveltejs kit
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SvelteKit 版本从 2.49.0 到 2.53.2(在 2.53.3 中修复)在实验性远程函数(experimental remote function)中存在反序列化扩展漏洞。当应用启用了 并使用 form 函数处理 files 数组时,若未验证 或单个文件大小,攻击者可以提交相对较小的输入,使其扩展为非常大的文件数组,从而引发高开销处理并导致服务拒绝(DoS)攻击。

CVSS 7.5 · High

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82259

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SvelteKit 2.49.0 before 2.53.3 Denial of Service via form
Source: CVE Program / CVE List V5
Vulnerability Description
SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to process the files array without validating files.length or individual file sizes, an attacker can submit relatively small inputs that expand into very large file arrays, leading to expensive processing and denial of service.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
sveltejs kit 2.49.0 ~ 2.53.3 -

II. Public POCs for CVE-2026-82259

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82259

登录查看更多情报信息。

Vendor Advisories for CVE-2026-82259 (2)

Same Patch Batch · sveltejs · 2026-08-28 · 6 CVEs total

CVE-2026-82260 7.5 HIGH SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization
CVE-2026-82261 7.5 HIGH SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserialization
CVE-2026-82258 5.9 MEDIUM SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batch
CVE-2026-82256 5.3 MEDIUM SvelteKit before 2.69.1 Denial of Service via Remote Form
CVE-2026-82257 4.3 MEDIUM SvelteKit before 2.69.1 Prototype Pollution via File Input

IV. Related Vulnerabilities

V. Comments for CVE-2026-82259

No comments yet


Leave a comment