Summary
SvelteKit: Big remote form function payloads can cause Node process to crash
Advisory details
Big remote form function payloads can cause the Node process to crash. Doing this repeatedly can cause DoS.
References
- https://github.com/advisories/GHSA-wqjv-9729-c5q2
- https://github.com/sveltejs/kit/security/advisories/GHSA-wqjv-9729-c5q2
- https://github.com/sveltejs/kit/pull/16219
- https://github.com/sveltejs/kit/commit/82b0370c793ac392cee5c2e28f4b8fed09c64582
- https://github.com/sveltejs/kit/releases/tag/@sveltejs/kit@2.69.1
- https://github.com/sveltejs/kit/releases/tag/@sveltejs/kit@3.0.0-next.7
Related vulnerabilities
All Supply chain →- MEDIUMCVE-2026-82417
qs: Denial of Service via Attacker Controlled isBuffer
- HIGHCVE-2026-73088
Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
- HIGHCVE-2026-55484
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
- MEDIUMCVE-2026-54553
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
- MEDIUMGHSA-rgqc-3x5p-6gwg
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
- MEDIUMCVE-2026-61799
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash