CVE-2026-82260 PUBLISHED

SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization

Assigner: VulnCheck
Reserved: 28.08.2026 Published: 28.08.2026 Updated: 28.08.2026

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause excessive memory allocation, crashing the server process and resulting in denial of service. Fixed in 2.52.2.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor sveltejs
Product kit
Versions Default: unaffected
  • affected from 2.49.0 to 2.52.1 (excl.)
  • Version 2.52.1 is unaffected

Credits

  • elliott-with-the-longest-name-on-github finder

References

Problem Types

  • Uncontrolled Resource Consumption CWE