CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-82259: sveltekit from 2.49.0 (inclusive), before 2.53.3 (exclusive); +1 more affected products

CVE-2026-82259. CVSS 3.1 base score 7.5 (HIGH, Vendor/CNA). EPSS 0.00533 (percentile 0.43115), scored 2026-10-06.

Affected technology

sveltekit · from 2.49.0 (inclusive), before 2.53.3 (exclusive)
svelte

kit · 2.49.0 to before 2.53.3
sveltejs

Description’s affected range: versions from 2.49.0 through 2.53.2 (fixed in 2.53.3)

Component: Not specified by the source
Function: to

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source says when an application enables experimental.remoteFunctions and uses the form function to process the files array without validating files.length or individual file sizes, an attacker can submit relatively small inputs that expand into very large file arrays, leading to expensive processing and denial of service. Vendor/CNA’s CVSS 4.0 assessment (base score 8.7/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-502
CCR priority
30.1 /100 (P4)
CVSS 3.1
7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · Vendor/CNA
EPSS
0.00533 · percentile 0.43213 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-82259.html