@sveltejs/kit vulnerabilities
CVEs whose affected-version data names the @sveltejs/kit package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-66062Medium· 5.3SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the content negotiation header parser used by SvelteKit's request handling (for headers such as Accept) uses a regular exp…
▾ Sunlitsveltejs · @sveltejs/kitEPSS 0.29%via NVD
GHSA-wqjv-9729-c5q2Medium· 5.3SvelteKit: Big remote form function payloads can cause Node process to crash
SvelteKit: Big remote form function payloads can cause Node process to crash
▾ Sunlitsveltejs · @sveltejs/kitvia GHSA
GHSA-866w-xmhq-wj7xMedium· 4.3SvelteKit: Prototype pollution in file input deletion path in remote-function forms
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
▾ Sunlitsveltejs · @sveltejs/kitvia GHSA