mediumVulnerability

GHSA-vrhm-gvg7-fpcf

Versions of `@sveltejs/kit` prior to 2.52.2 with remote functions enabled can be vulnerable to memory exhaustion. Malformed form data can cause the server process to crash due to excessive memory allocation, resulting in denial of service. Only applications using both `experimental.remoteFunctions` and `form` are vulnerable.

Properties

ghsa_id
GHSA-vrhm-gvg7-fpcf
severity
medium
summary
Memory exhaustion in SvelteKit remote form deserialization (experimental only)
cve_id
GHSA-vrhm-gvg7-fpcf
is_ghsa_only
true
ghsa_published
2026-02-19T20:29:42Z
source_url
https://github.com/advisories/GHSA-vrhm-gvg7-fpcf
ghsa_updated
2026-02-19T20:29:43Z

Related Entities (3)

AFFECTS (1)

[Software]npm/@sveltejs/kit

HAS_WEAKNESS (1)

[Weakness]Allocation of Resources Without Limits or Throttling

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-vrhm-gvg7-fpcf — Ninja Signal Threat Intelligence | Ninja Signal