CVE-2026-42567

Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}></svelte:element>. This issue has been patched in version 5.55.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:svelte:svelte:*:*:*:*:*:node.js:*:*

History

11 Jun 2026, 18:54

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:svelte:svelte:*:*:*:*:*:node.js:*:*
First Time Svelte svelte
Svelte
References () https://github.com/sveltejs/svelte/releases/tag/svelte%405.55.7 - () https://github.com/sveltejs/svelte/releases/tag/svelte%405.55.7 - Product, Release Notes
References () https://github.com/sveltejs/svelte/security/advisories/GHSA-9rmh-mm8f-r9h6 - () https://github.com/sveltejs/svelte/security/advisories/GHSA-9rmh-mm8f-r9h6 - Vendor Advisory

09 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 17:17

Updated : 2026-06-11 18:54


NVD link : CVE-2026-42567

Mitre link : CVE-2026-42567

CVE.ORG link : CVE-2026-42567


JSON object : View

Products Affected

svelte

  • svelte
CWE
CWE-1333

Inefficient Regular Expression Complexity