CVE-2026-82256 MEDIUM

CVE-2026-82256: SvelteKit before 2.69.1 Denial of Service via Remote Form

Vendor Sveltejs
Product kit
Weakness CWE-400
Published August 28, 2026
Last update August 28, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly crashing the application process.

Key dates

02Disclosure timeline

August 28, 2026 CVE published
August 28, 2026 Record updated