CVE-2026-22803

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4, the experimental form remote function uses a binary data format containing a representation of submitted form data. A specially-crafted payload can cause the server to allocate a large amount of memory, causing DoS via memory exhaustion. This vulnerability is fixed in 2.49.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:svelte:kit:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 10:20

Type Values Removed Values Added
Summary
  • (es) SvelteKit es un framework para desarrollar rápidamente aplicaciones web robustas y de alto rendimiento utilizando Svelte. Desde la versión 2.49.0 hasta la 2.49.4, la función remota experimental de formularios utiliza un formato de datos binarios que contiene una representación de los datos de formulario enviados. Una carga útil especialmente diseñada puede hacer que el servidor asigne una gran cantidad de memoria, causando DoS por agotamiento de memoria. Esta vulnerabilidad está corregida en la versión 2.49.5.

21 Jan 2026, 20:34

Type Values Removed Values Added
First Time Svelte
Svelte kit
CWE CWE-770
CPE cpe:2.3:a:svelte:kit:*:*:*:*:*:node.js:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://github.com/sveltejs/kit/commit/8ed8155215b9a74012fecffb942ad9a793b274e5 - () https://github.com/sveltejs/kit/commit/8ed8155215b9a74012fecffb942ad9a793b274e5 - Patch
References () https://github.com/sveltejs/kit/releases/tag/@sveltejs%2Fadapter-node@5.5.1 - () https://github.com/sveltejs/kit/releases/tag/@sveltejs%2Fadapter-node@5.5.1 - Release Notes
References () https://github.com/sveltejs/kit/security/advisories/GHSA-j2f3-wq62-6q46 - () https://github.com/sveltejs/kit/security/advisories/GHSA-j2f3-wq62-6q46 - Vendor Advisory

15 Jan 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 19:16

Updated : 2026-06-17 10:20


NVD link : CVE-2026-22803

Mitre link : CVE-2026-22803

CVE.ORG link : CVE-2026-22803


JSON object : View

Products Affected

svelte

  • kit
CWE
CWE-789

Memory Allocation with Excessive Size Value

CWE-770

Allocation of Resources Without Limits or Throttling