CVE-2026-82260 HIGH

CVE-2026-82260: SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization

Vendor Sveltejs
Product kit
Weakness CWE-400
Published August 28, 2026
Last update August 28, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause excessive memory allocation, crashing the server process and resulting in denial of service. Fixed in 2.52.2.

Key dates

02Disclosure timeline

August 28, 2026 CVE published
August 28, 2026 Record updated