MEDIUM🇬🇧 English

CVE-2026-40074

CVSS 6.3v4.0pub. 2026-04-10upd. 2026-04-15

SvelteKit to framework do szybkiego tworzenia solidnych i wydajnych aplikacji internetowych przy użyciu Svelte. Przed wersją 2.57.1 funkcja redirect wywołana wewnątrz hook'a handle z parametrem location zawierającym znaki nieprawidłowe w nagłówku HTTP powodowała nieobsługiwany TypeError. Mogło to skutkować DoS na niektórych platformach, szczególnie jeśli lokalizacja przekazana do redirect zawierała niezasanizowane dane użytkownika. Luka została naprawiona w wersji 2.57.1.

Pokaż oryginał (EN)

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, redirect, when called from inside the handle server hook with a location parameter containing characters that are invalid in a HTTP header, will cause an unhandled TypeError. This could result in DoS on some platforms, especially if the location passed to redirect contains unsanitized user input. This vulnerability is fixed in 2.57.1.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Svelte Kit

    APP
    Svelte
    < 2.57.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2026-40073HIGH8.2ten sam produkt

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.5...

CVE-2025-67647HIGH8.4ten sam produkt

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.4...

CVE-2026-22803HIGH8.2ten sam produkt

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 ...

CVE-2024-23641HIGH7.5ten sam produkt

SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and p...

CVE-2026-82259HIGH8.7ten sam vendor

SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in t...