{"id":"CVE-2026-82260","title":"SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization","summary":"SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400"],"vendor":"svelte","product":"sveltekit","affected":["sveltekit >= 2.49.0, < 2.52.2"],"patched":["sveltekit 2.52.2"],"published":"2026-08-28","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:48.803","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82260","references":[{"url":"https://github.com/sveltejs/kit/security/advisories/GHSA-vrhm-gvg7-fpcf","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/sveltekit-before-2.52.2-memory-exhaustion-via-remote-form-deserialization","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-08-28T14:42:03.280810Z"},"epss":0.00493,"epssPercentile":0.40382,"ingestedAt":"2026-10-08T16:52:14.734Z","slug":"CVE-2026-82260","body":"## Overview\n\nSvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause excessive memory allocation, crashing the server process and resulting in denial of service. Fixed in 2.52.2.\n\n## Affected\n\n- `sveltekit >= 2.49.0, < 2.52.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `sveltekit 2.52.2`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}