vciy

CVEs we hold for Sveltejs

Records whose assigning authority named Sveltejs as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-92708devalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval` serialize Node Bufferssveltejs devalue
CVE-2026-82261SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserializationsveltejs kit
CVE-2026-82260SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserializationsveltejs kit
CVE-2026-82259SvelteKit 2.49.0 before 2.53.3 Denial of Service via formsveltejs kit
CVE-2026-82258SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batchsveltejs kit
CVE-2026-82257SvelteKit before 2.69.1 Prototype Pollution via File Inputsveltejs kit
CVE-2026-82256SvelteKit before 2.69.1 Denial of Service via Remote Formsveltejs kit
CVE-2026-81176Svelte devalue: DoS via malformed inputsveltejs devalue
CVE-2026-66062SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept headersveltejs kit
CVE-2026-42599Cross-site scripting via spread attributes in Svelte SSRsveltejs svelte
CVE-2026-42573Svelte: XSS via DOM Clobbering of Internal Framework Statesveltejs svelte
CVE-2026-42570Svelte devalue: DoS via sparse array deserializationsveltejs devalue
CVE-2026-42567Svelte: ReDoS in `<svelte:element>` Tag Validationsveltejs svelte
CVE-2026-40074SvelteKit's invalidated redirect in handle hook causes Denial-of-Servicesveltejs kit
CVE-2026-40073SvelteKit has a BODY_SIZE_LIMIT bypass in @sveltejs/adapter-nodesveltejs kit
CVE-2026-30226devalue has prototype pollution in devalue.parse and devalue.unflattensveltejs devalue
CVE-2026-27902Svelte Vulnerable to XSS via HTML Comment Injection in SSR Error Boundary Hydration Markerssveltejs svelte
CVE-2026-27901Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`sveltejs svelte
CVE-2026-27125Svelte SSR attribute spreading includes inherited properties from prototype chainsveltejs svelte
CVE-2026-27122Svelte SSR does not validate dynamic element tag names in `<svelte:element>`sveltejs svelte
CVE-2026-27121Svelte affected by cross-site scripting via spread attributes in Svelte SSRsveltejs svelte
CVE-2026-27119Svelte affected by XSS in SSR `<option>` elementsveltejs svelte
CVE-2026-27118Cache poisoning in @sveltejs/adapter-vercelsveltejs kit
CVE-2026-22803SvelteKit has a memory amplification DoS in Remote Functions binary form deserializersveltejs kit
CVE-2026-22775devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parsesveltejs devalue
CVE-2026-22774devalue vulnerable to denial of service due to memory exhaustion in devalue.parsesveltejs devalue
CVE-2025-67647SvelteKit Denial of service and possible SSRF when using prerenderingsveltejs kit
CVE-2025-57820Svelte devalue vulnerable to prototype pollutionsveltejs devalue
CVE-2025-32388SvelteKit allows XSS via tracked search_paramssveltejs kit
CVE-2024-53262Unescaped error message included on error page in SvelteKitsveltejs kit
CVE-2024-53261Cross-Site Scripting attack (XSS) on dev mode 404 page in SvelteKitsveltejs kit
CVE-2024-45047Potential mXSS vulnerability due to improper HTML escaping in sveltesveltejs svelte
CVE-2024-23641Sending a GET or HEAD request with a body crashes SvelteKitsveltejs kit
CVE-2023-29008SvelteKit framework has Insufficient CSRF protection for CORS requestssveltejs kit
CVE-2023-29003SvelteKit has Insufficient Cross-Site Request Forgery Protectionsveltejs kit

35 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.