Description
SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly crashing the application process.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 28 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly crashing the application process. | |
| Title | SvelteKit before 2.69.1 Denial of Service via Remote Form | |
| First Time appeared |
Svelte
Svelte kit |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:svelte:kit:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Svelte
Svelte kit |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T10:49:40.634Z
Reserved: 2026-08-28T10:39:30.355Z
Link: CVE-2026-82256
No data.
Status : Received
Published: 2026-08-28T12:16:38.457
Modified: 2026-08-28T12:16:38.457
Link: CVE-2026-82256
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-400
Uncontrolled Resource Consumption