Svelte
Sveltekit: vulnerabilidades y CVE
Sveltekit tiene 14 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses8
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-92708 | Alta (7.5) | 0.73% | — | 18 sept 2026 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by… |
| CVE-2026-82261 | Alta (8.7) | 0.49% | — | 28 ago 2026 | SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send malformed form data to… |
| CVE-2026-82260 | Alta (8.7) | 0.49% | — | 28 ago 2026 | SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization.… |
| CVE-2026-82259 | Alta (8.7) | 0.53% | — | 28 ago 2026 | SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the… |
| CVE-2026-82258 | Media (5.9) | 0.24% | — | 28 ago 2026 | SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploit specific timing… |
| CVE-2026-82257 | Media (5.3) | 0.36% | — | 28 ago 2026 | SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path… |
| CVE-2026-82256 | Media (6.9) | 0.42% | — | 28 ago 2026 | SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly… |
| CVE-2026-66062 | Media (5.3) | 0.51% | — | 7 ago 2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the content negotiation header parser used by SvelteKit's request handling (for headers such as Accept)… |
| CVE-2025-32388 | Media (5.4) | 0.30% | — | 15 abr 2025 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.20.6 , unsanitized search param names cause XSS vulnerability. You are affected if you iterate over all… |
| CVE-2024-53262 | Baja (2) | 0.48% | — | 25 nov 2024 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html template for errors contains placeholders that are replaced without escaping the content first.… |
| CVE-2024-53261 | Baja (2) | 0.33% | — | 25 nov 2024 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. "Unsanitized input from *the request URL* flows into `end`, where it is used to render an HTML page returned to the user.… |
| CVE-2024-34354 | Media (6.5) | 0.29% | — | 14 may 2024 | CMSaaSStarter is a SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Any forks of the CMSaaSStarter template before commit 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 are impacted. The issue is the… |
| CVE-2023-29008 | Alta (8.8) | 0.37% | — | 6 abr 2023 | The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box… |
| CVE-2023-29003 | Alta (8.8) | 0.56% | — | 4 abr 2023 | SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.