CVEs we hold for Sveltejs
Records whose assigning authority named Sveltejs as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-92708devalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval` serialize Node Bufferssveltejs devalue CVE-2026-82261SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserializationsveltejs kit CVE-2026-82260SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserializationsveltejs kit CVE-2026-82259SvelteKit 2.49.0 before 2.53.3 Denial of Service via formsveltejs kit CVE-2026-82258SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batchsveltejs kit CVE-2026-82257SvelteKit before 2.69.1 Prototype Pollution via File Inputsveltejs kit CVE-2026-82256SvelteKit before 2.69.1 Denial of Service via Remote Formsveltejs kit CVE-2026-66062SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept headersveltejs kit CVE-2026-42599Cross-site scripting via spread attributes in Svelte SSRsveltejs svelte CVE-2026-42573Svelte: XSS via DOM Clobbering of Internal Framework Statesveltejs svelte CVE-2026-42570Svelte devalue: DoS via sparse array deserializationsveltejs devalue CVE-2026-42567Svelte: ReDoS in `<svelte:element>` Tag Validationsveltejs svelte CVE-2026-40074SvelteKit's invalidated redirect in handle hook causes Denial-of-Servicesveltejs kit CVE-2026-40073SvelteKit has a BODY_SIZE_LIMIT bypass in @sveltejs/adapter-nodesveltejs kit CVE-2026-30226devalue has prototype pollution in devalue.parse and devalue.unflattensveltejs devalue CVE-2026-27902Svelte Vulnerable to XSS via HTML Comment Injection in SSR Error Boundary Hydration Markerssveltejs svelte CVE-2026-27901Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`sveltejs svelte CVE-2026-27125Svelte SSR attribute spreading includes inherited properties from prototype chainsveltejs svelte CVE-2026-27122Svelte SSR does not validate dynamic element tag names in `<svelte:element>`sveltejs svelte CVE-2026-27121Svelte affected by cross-site scripting via spread attributes in Svelte SSRsveltejs svelte CVE-2026-27119Svelte affected by XSS in SSR `<option>` elementsveltejs svelte CVE-2026-22803SvelteKit has a memory amplification DoS in Remote Functions binary form deserializersveltejs kit CVE-2026-22775devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parsesveltejs devalue CVE-2026-22774devalue vulnerable to denial of service due to memory exhaustion in devalue.parsesveltejs devalue CVE-2025-67647SvelteKit Denial of service and possible SSRF when using prerenderingsveltejs kit CVE-2025-57820Svelte devalue vulnerable to prototype pollutionsveltejs devalue CVE-2025-32388SvelteKit allows XSS via tracked search_paramssveltejs kit CVE-2024-53262Unescaped error message included on error page in SvelteKitsveltejs kit CVE-2024-53261Cross-Site Scripting attack (XSS) on dev mode 404 page in SvelteKitsveltejs kit CVE-2024-45047Potential mXSS vulnerability due to improper HTML escaping in sveltesveltejs svelte CVE-2024-23641Sending a GET or HEAD request with a body crashes SvelteKitsveltejs kit CVE-2023-29008SvelteKit framework has Insufficient CSRF protection for CORS requestssveltejs kit CVE-2023-29003SvelteKit has Insufficient Cross-Site Request Forgery Protectionsveltejs kit 35 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.