CVE-2026-42567: Svelte
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}></svelte:element>. This issue has been patched in version 5.55.7.
Affected products
- Svelte Svelte: from 5.51.5, before 5.55.7 (fixed in 5.55.7)
Published 2026-06-09. Last modified 2026-07-23.