kit
sveltejs- Product type
- Other
- Catalog vulnerabilities
- 18
Severity across 18 analyzed records
Verify to analyze this security profile
en
As of 09/19/2026, within CyStack's analyzed data, kit has 7 security vulnerabilities published in the last 90 days. Of these, 3 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of kit and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-82261SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserialization | Exploitation statusNot known exploited | FixYes | Published08/28/2026 | SeverityHigh |
CVE-2026-82260SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization | Exploitation statusNot known exploited | FixYes | Published08/28/2026 | SeverityHigh |
CVE-2026-82259SvelteKit 2.49.0 before 2.53.3 Denial of Service via form | Exploitation statusNot known exploited | FixYes | Published08/28/2026 | SeverityHigh |
CVE-2026-82258SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batch | Exploitation statusNot known exploited | FixYes | Published08/28/2026 | SeverityMedium |
CVE-2026-82257SvelteKit before 2.69.1 Prototype Pollution via File Input | Exploitation statusNot known exploited | FixYes | Published08/28/2026 | SeverityMedium |
CVE-2026-82256SvelteKit before 2.69.1 Denial of Service via Remote Form | Exploitation statusNot known exploited | FixYes | Published08/28/2026 | SeverityMedium |
CVE-2026-66062SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header | Exploitation statusNot known exploited | FixNot confirmed | Published08/07/2026 | SeverityMedium |
CVE-2026-40074SvelteKit's invalidated redirect in handle hook causes Denial-of-Service | Exploitation statusNot known exploited | FixYes | Published04/10/2026 | SeverityMedium |
CVE-2026-40073SvelteKit has a BODY_SIZE_LIMIT bypass in @sveltejs/adapter-node | Exploitation statusNot known exploited | FixYes | Published04/10/2026 | SeverityHigh |
CVE-2026-27118Cache poisoning in @sveltejs/adapter-vercel | Exploitation statusNot known exploited | FixYes | Published02/20/2026 | SeverityMedium |
CVE-2026-22803SvelteKit has a memory amplification DoS in Remote Functions binary form deserializer | Exploitation statusNot known exploited | FixYes | Published01/15/2026 | SeverityHigh |
CVE-2025-67647SvelteKit Denial of service and possible SSRF when using prerendering | Exploitation statusNot known exploited | FixYes | Published01/15/2026 | SeverityHigh |
CVE-2025-32388SvelteKit allows XSS via tracked search_params | Exploitation statusPublic exploit | FixYes | Published04/15/2025 | SeverityMedium |
CVE-2024-53261Cross-Site Scripting attack (XSS) on dev mode 404 page in SvelteKit | Exploitation statusNot known exploited | FixNot confirmed | Published11/25/2024 | SeverityLow |
CVE-2024-53262Unescaped error message included on error page in SvelteKit | Exploitation statusNot known exploited | FixNot confirmed | Published11/25/2024 | SeverityLow |
CVE-2024-23641Sending a GET or HEAD request with a body crashes SvelteKit | Exploitation statusPublic exploit | FixNot confirmed | Published01/24/2024 | SeverityHigh |
CVE-2023-29008SvelteKit framework has Insufficient CSRF protection for CORS requests | Exploitation statusPublic exploit | FixNot confirmed | Published04/06/2023 | SeverityHigh |
CVE-2023-29003SvelteKit has Insufficient Cross-Site Request Forgery Protection | Exploitation statusPublic exploit | FixNot confirmed | Published04/04/2023 | SeverityHigh |