CVE-2026-27118

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Versions of @sveltejs/adapter-vercel prior to 6.3.2 are vulnerable to cache poisoning. An internal query parameter intended for Incremental Static Regeneration (ISR) is accessible on all routes, allowing an attacker to cause sensitive user-specific responses to be cached and served to other users. Successful exploitation requires a victim to visit an attacker-controlled link while authenticated. Existing deployments are protected by Vercel's WAF, but users should upgrade as soon as possible. This vulnerability is fixed in 6.3.2.
CVSS

No CVSS.

Configurations

No configuration.

History

20 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-20 22:16

Updated : 2026-02-23 18:14


NVD link : CVE-2026-27118

Mitre link : CVE-2026-27118

CVE.ORG link : CVE-2026-27118


JSON object : View

Products Affected

No product.

CWE
CWE-346

Origin Validation Error