{"id":"CVE-2026-82258","title":"SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context","summary":"SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploit specific timing conditions to access…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","cwe":["CWE-362"],"vendor":"svelte","product":"sveltekit","affected":["sveltekit >= 2.38.0, < 2.60.1"],"patched":["sveltekit 2.60.1"],"published":"2026-08-28","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:48.457","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82258","references":[{"url":"https://github.com/sveltejs/kit/security/advisories/GHSA-hgv7-v322-mmgr","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/sveltekit-2.38.0-before-2.60.1-cross-user-data-disclosure-via-query-batch","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-31T18:36:10.682520Z"},"scores":{"nvd":4.8,"cna":5.9},"epss":0.00235,"epssPercentile":0.13241,"ingestedAt":"2026-10-08T16:52:14.734Z","slug":"CVE-2026-82258","body":"## Overview\n\nSvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploit specific timing conditions to access sensitive data from other users' concurrent requests.\n\n## Affected\n\n- `sveltekit >= 2.38.0, < 2.60.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `sveltekit 2.60.1`","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}