Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

kit — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in kit, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the vendor kit, focusing on common weakness types and related security tags. It collects and organizes reported security vulnerabilities associated with the kit product line, covering a historical range from early discoveries up to the most recently disclosed incidents. By consolidating data from multiple sources, the platform ensures that users have access to a comprehensive view of the security landscape surrounding this specific software ecosystem. Readers can use this resource to track a vendor's advisories, allowing them to stay informed about official patch releases and mitigation strategies. Additionally, the page enables users to understand a weakness class by analyzing patterns and common root causes within the kit’s codebase or configuration. You can also look up a product's vulnerability history to assess long-term security trends and identify recurring issues. This structured approach helps security professionals, developers, and system administrators make informed decisions regarding risk management and remediation efforts. The content is updated regularly to reflect the latest findings and is presented in a neutral, factual manner to facilitate accurate analysis. By providing clear references and contextual information, this page serves as a practical tool for evaluating the security posture of kit-related assets.

Vendor: sveltejs

CVE ID Title CVSS Severity Published
CVE-2026-82261 SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserialization CWE-400 7.5 High 2026-08-28
CVE-2026-82260 SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization CWE-400 7.5 High 2026-08-28
CVE-2026-82259 SvelteKit 2.49.0 before 2.53.3 Denial of Service via form CWE-502 7.5 High 2026-08-28
CVE-2026-82258 SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batch CWE-362 5.9 Medium 2026-08-28
CVE-2026-82256 SvelteKit before 2.69.1 Denial of Service via Remote Form CWE-400 5.3 Medium 2026-08-28
CVE-2026-82257 SvelteKit before 2.69.1 Prototype Pollution via File Input CWE-1321 4.3 Medium 2026-08-28
CVE-2026-66062 SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header CWE-1333 5.3 Medium 2026-08-07
CVE-2026-40074 SvelteKit's invalidated redirect in handle hook causes Denial-of-Service CWE-755 6.5 - 2026-04-10
CVE-2026-40073 SvelteKit has a BODY_SIZE_LIMIT bypass in @sveltejs/adapter-node CWE-770 5.3 - 2026-04-10
CVE-2026-27118 Cache poisoning in @sveltejs/adapter-vercel CWE-346 5.4AI Medium AI 2026-02-20
CVE-2026-22803 SvelteKit has a memory amplification DoS in Remote Functions binary form deserializer CWE-789 7.5AI High AI 2026-01-15
CVE-2025-67647 SvelteKit Denial of service and possible SSRF when using prerendering CWE-248 7.5AI High AI 2026-01-15
CVE-2025-32388 SvelteKit allows XSS via tracked search_params CWE-79 5.4 Medium 2025-04-15
CVE-2024-53261 Cross-Site Scripting attack (XSS) on dev mode 404 page in SvelteKit CWE-79 6.1AI Medium AI 2024-11-25
CVE-2024-53262 Unescaped error message included on error page in SvelteKit CWE-79 7.1AI High AI 2024-11-25
CVE-2024-23641 Sending a GET or HEAD request with a body crashes SvelteKit CWE-20 7.5 High 2024-01-24
CVE-2023-29008 SvelteKit framework has Insufficient CSRF protection for CORS requests CWE-918 8.8 High 2023-04-06
CVE-2023-29003 SvelteKit has Insufficient Cross-Site Request Forgery Protection CWE-352 8.8 High 2023-04-04

All 18 known CVE vulnerabilities affecting kit with full Chinese analysis, references, and POCs where available.