CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-82261: sveltekit from 2.49.0 (inclusive), before 2.52.2 (exclusive); +1 more affected products

CVE-2026-82261. CVSS 3.1 base score 7.5 (HIGH, Vendor/CNA). EPSS 0.00493 (percentile 0.40296), scored 2026-10-06.

Affected technology

sveltekit · from 2.49.0 (inclusive), before 2.52.2 (exclusive)
svelte

kit · 2.49.0 to before 2.52.1
sveltejs

Description’s affected range: versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

An attacker can send malformed form data to cause the server to become unresponsive while processing the request, resulting in denial of service. Vendor/CNA’s CVSS 4.0 assessment (base score 8.7/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-400
CCR priority
30.1 /100 (P4)
CVSS 3.1
7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · Vendor/CNA
EPSS
0.00493 · percentile 0.40407 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-82261.html