mediumVulnerability
GHSA-88qp-p4qg-rqm6
Versions of `@sveltejs/kit` prior to 2.52.2 with remote functions enabled are vulnerable to CPU exhaustion. Malformed form data can cause the server to become unresponsive while processing a request, resulting in denial of service. Only applications using both `experimental.remoteFunctions` and `form` are vulnerable.
Properties
- ghsa_id
- GHSA-88qp-p4qg-rqm6
- severity
- medium
- summary
- CPU exhaustion in SvelteKit remote form deserialization (experimental only)
- cve_id
- GHSA-88qp-p4qg-rqm6
- is_ghsa_only
- true
- ghsa_published
- 2026-02-19T20:30:25Z
- source_url
- https://github.com/advisories/GHSA-88qp-p4qg-rqm6
- ghsa_updated
- 2026-02-19T20:30:29Z
Related Entities (3)
AFFECTS (1)
→[Software]npm/@sveltejs/kit
HAS_WEAKNESS (1)
→[Weakness]Access of Resource Using Incompatible Type ('Type Confusion')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph