HIGH🇵🇱 Wersja polska

CVE-2026-40073

CVSS 8.2v4.0pub. 2026-04-10upd. 2026-04-15

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under certain circumstances, requests could bypass the BODY_SIZE_LIMIT on SvelteKit applications running with adapter-node. This bypass does not affect body size limits at other layers of the application stack, so limits enforced in the WAF, gateway, or at the platform level are unaffected. This vulnerability is fixed in 2.57.1.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Svelte Kit

    APP
    Svelte
    < 2.57.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-67647HIGH8.4same product

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.4...

CVE-2026-22803HIGH8.2same product

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 ...

CVE-2024-23641HIGH7.5same product

SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and p...

CVE-2026-40074MEDIUM6.3same product

SvelteKit to framework do szybkiego tworzenia solidnych i wydajnych aplikacji internetowych przy użyciu Svelte...

CVE-2026-82259HIGH8.7same vendor

SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in t...