MEDIUMVulnerability

CVE-2026-82256

SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly crashing the application process.

Properties

severity
MEDIUM
score
5.3
epss_score
0.00247
cve_id
CVE-2026-82256
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
published_at
2026-08-28T12:16:38.457
last_modified
2026-08-31T22:22:17.743
epss_percentile
0.1588

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

[Product]

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Uncontrolled Resource Consumption

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82256 — Ninja Signal Threat Intelligence | Ninja Signal