lowVulnerability

GHSA-fpg4-jhqr-589c

Some relatively small inputs can cause very large files arrays in `form` handlers. If the SvelteKit application code doesn't check `files.length` or individual files' sizes and performs expensive processing with them, it can result in Denial of Service. Only users with `experimental.remoteFunctions: true` who are using the `form` function and are processing the `files` array without validation are vulnerable.

Properties

ghsa_id
GHSA-fpg4-jhqr-589c
severity
low
summary
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
cve_id
GHSA-fpg4-jhqr-589c
is_ghsa_only
true
ghsa_published
2026-02-28T02:04:39Z
source_url
https://github.com/advisories/GHSA-fpg4-jhqr-589c
ghsa_updated
2026-02-28T02:04:40Z

Related Entities (3)

AFFECTS (1)

[Software]npm/@sveltejs/kit

HAS_WEAKNESS (1)

[Weakness]Allocation of Resources Without Limits or Throttling

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-fpg4-jhqr-589c — Ninja Signal Threat Intelligence | Ninja Signal