---
id: CVE-2026-82256
title: >-
  SvelteKit before 2.69.1 fails to properly validate remote form function
  payload sizes, allowing attackers to crash the Node process by sending large
  payloads
summary: >-
  SvelteKit before 2.69.1 fails to properly validate remote form function
  payload sizes, allowing attackers to crash the Node process by sending large
  payloads. Repeated exploitation causes denial of service by repeatedly
  crashing the appl…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-400
vendor: svelte
product: sveltekit
affected:
  - sveltekit < 2.69.1
patched:
  - sveltekit 2.69.1
published: '2026-08-28'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:48.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82256'
references:
  - url: 'https://github.com/sveltejs/kit/security/advisories/GHSA-wqjv-9729-c5q2'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/sveltekit-before-2.69.1-denial-of-service-via-remote-form
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-28T14:41:26.205777Z'
epss: 0.00423
epssPercentile: 0.34547
ingestedAt: '2026-10-08T16:52:14.733Z'
---

## Overview

SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly crashing the application process.

## Affected

- `sveltekit < 2.69.1`

## Remediation

Upgrade past the affected range:

- `sveltekit 2.69.1`
