CVE-2026-22803: Svelte Kit

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4, the experimental form remote function uses a binary data format containing a representation of submitted form data. A specially-crafted payload can cause the server to allocate a large amount of memory, causing DoS via memory exhaustion. This vulnerability is fixed in 2.49.5.

Affected products

  • Svelte Kit: from 2.49.0, before 2.49.5 (fixed in 2.49.5)

Published 2026-01-15. Last modified 2026-06-17.