mediumVulnerability

GHSA-88qp-p4qg-rqm6

Versions of `@sveltejs/kit` prior to 2.52.2 with remote functions enabled are vulnerable to CPU exhaustion. Malformed form data can cause the server to become unresponsive while processing a request, resulting in denial of service. Only applications using both `experimental.remoteFunctions` and `form` are vulnerable.

Properties

ghsa_id
GHSA-88qp-p4qg-rqm6
severity
medium
summary
CPU exhaustion in SvelteKit remote form deserialization (experimental only)
cve_id
GHSA-88qp-p4qg-rqm6
is_ghsa_only
true
ghsa_published
2026-02-19T20:30:25Z
source_url
https://github.com/advisories/GHSA-88qp-p4qg-rqm6
ghsa_updated
2026-02-19T20:30:29Z

Related Entities (3)

AFFECTS (1)

[Software]npm/@sveltejs/kit

HAS_WEAKNESS (1)

[Weakness]Access of Resource Using Incompatible Type ('Type Confusion')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-88qp-p4qg-rqm6 — Ninja Signal Threat Intelligence | Ninja Signal