Svelte
Svelte KIT: vulnerabilidades y CVE
Svelte KIT tiene 6 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-65472 | Media (5.3) | 0.29% | — | 23 jul 2026 | Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions. |
| CVE-2026-40074 | Media (6.3) | 0.61% | — | 10 abr 2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, redirect, when called from inside the handle server hook with a location parameter containing characters… |
| CVE-2026-40073 | Alta (8.2) | 0.95% | — | 10 abr 2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under certain circumstances, requests could bypass the BODY_SIZE_LIMIT on SvelteKit applications running… |
| CVE-2026-22803 | Alta (8.2) | 0.60% | — | 15 ene 2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4, the experimental form remote function uses a binary data format containing a representation of… |
| CVE-2025-67647 | Alta (8.4) | 0.53% | — | 15 ene 2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, SvelteKit is vulnerable to a server side request forgery (SSRF) and denial of service (DoS) under… |
| CVE-2024-23641 | Alta (7.5) | 0.76% | — | 24 ene 2024 | SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/hosted sveltekit app throws `Request with GET/HEAD method cannot have body.` and crashes the… |