mediumVulnerability

GHSA-hgv7-v322-mmgr

`query.batch()` could, under very rare and specific timings, cause concurrent requests from different users to merge and resolve under single request context, enabling cross-user data disclosure.

Properties

ghsa_id
GHSA-hgv7-v322-mmgr
severity
medium
summary
@sveltejs/kit: `query.batch` cross-talk
cve_id
GHSA-hgv7-v322-mmgr
is_ghsa_only
true
ghsa_published
2026-05-21T17:59:05Z
source_url
https://github.com/advisories/GHSA-hgv7-v322-mmgr
ghsa_updated
2026-05-21T17:59:06Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Exposure of Sensitive Information to an Unauthorized Actor

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/@sveltejs/kit

AFFECTS (1)

[Software]npm/@sveltejs/kit

Explore deeper with Ninja Signal's threat intelligence graph