GHSA-wqjv-9729-c5q2Medium· 5.3▾ SunlitSvelteKit: Big remote form function payloads can cause Node process to crash
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Big remote form function payloads can cause the Node process to crash. Doing this repeatedly can cause DoS.
@sveltejs/kit <= 2.69.0Upgrade to a patched release:
@sveltejs/kit 2.69.1Connected by shared product, vendor, weakness, or advisory.
GHSA-866w-xmhq-wj7xMedium· 4.3SvelteKit: Prototype pollution in file input deletion path in remote-function forms
CVE-2026-66062Medium· 5.3SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte
CVE-2026-44001High· 8.6vm2 is an open source vm/sandbox for Node.js
CVE-2026-31812Medium· 5.3Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol
CVE-2026-62985High· 7.5request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses
CVE-2026-92708High· 7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job