CVE-2026-40073

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under certain circumstances, requests could bypass the BODY_SIZE_LIMIT on SvelteKit applications running with adapter-node. This bypass does not affect body size limits at other layers of the application stack, so limits enforced in the WAF, gateway, or at the platform level are unaffected. This vulnerability is fixed in 2.57.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:svelte:kit:*:*:*:*:*:node.js:*:*

History

15 Apr 2026, 18:43

Type Values Removed Values Added
First Time Svelte
Svelte kit
References () https://github.com/sveltejs/kit/commit/3202ed6c98f9e8d86bf0c4c7ad0f2e273e5e3b95 - () https://github.com/sveltejs/kit/commit/3202ed6c98f9e8d86bf0c4c7ad0f2e273e5e3b95 - Patch
References () https://github.com/sveltejs/kit/releases/tag/@sveltejs/kit@2.57.1 - () https://github.com/sveltejs/kit/releases/tag/@sveltejs/kit@2.57.1 - Product, Release Notes
References () https://github.com/sveltejs/kit/security/advisories/GHSA-2crg-3p73-43xp - () https://github.com/sveltejs/kit/security/advisories/GHSA-2crg-3p73-43xp - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:svelte:kit:*:*:*:*:*:node.js:*:*

10 Apr 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-10 17:17

Updated : 2026-04-15 18:43


NVD link : CVE-2026-40073

Mitre link : CVE-2026-40073

CVE.ORG link : CVE-2026-40073


JSON object : View

Products Affected

svelte

  • kit
CWE
CWE-770

Allocation of Resources Without Limits or Throttling