Vulnerabilidades en sveltejs
35 resultadosAnálisis Vexday
Sveltejs apresenta 26 vulnerabilidades conhecidas na base, nenhuma sob exploração ativa no momento. A ameaça dominante é cross-site scripting (CWE-79), com 4 novas publicações nos últimos 90 dias indicando descoberta contínua de falhas. Ausência de críticas CVSS sugere risco moderado, mas a recência das divulgações recomenda atenção a atualizações.
CVE-2026-40073HIGHSvelteKit has a BODY_SIZE_LIMIT bypass in @sveltejs/adapter-nodeEPSS 1.0%CVE-2024-23641HIGHSending a GET or HEAD request with a body crashes SvelteKitEPSS 0.8%CVE-2026-42570HIGHSvelte devalue: DoS via sparse array deserializationEPSS 0.7%CVE-2026-22775HIGHdevalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parseEPSS 0.6%CVE-2026-22774HIGHdevalue vulnerable to denial of service due to memory exhaustion in devalue.parseEPSS 0.6%CVE-2026-40074MEDIUMSvelteKit's invalidated redirect in handle hook causes Denial-of-ServiceEPSS 0.6%CVE-2026-22803HIGHSvelteKit has a memory amplification DoS in Remote Functions binary form deserializerEPSS 0.6%CVE-2026-92708HIGHdevalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval` serialize Node BuffersEPSS 0.6%CVE-2023-29003HIGHSvelteKit has Insufficient Cross-Site Request Forgery ProtectionEPSS 0.6%CVE-2026-82259HIGHSvelteKit 2.49.0 before 2.53.3 Denial of Service via formEPSS 0.5%CVE-2025-67647HIGHSvelteKit Denial of service and possible SSRF when using prerenderingEPSS 0.5%CVE-2026-66062MEDIUMSvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept headerEPSS 0.5%CVE-2026-81176MEDIUMSvelte devalue: DoS via malformed inputEPSS 0.5%CVE-2026-27125MEDIUMSvelte SSR attribute spreading includes inherited properties from prototype chainEPSS 0.5%CVE-2026-30226MEDIUMdevalue has prototype pollution in devalue.parse and devalue.unflattenEPSS 0.5%CVE-2026-82261HIGHSvelteKit before 2.52.2 CPU Exhaustion via Remote Form DeserializationEPSS 0.5%CVE-2026-82260HIGHSvelteKit before 2.52.2 Memory Exhaustion via Remote Form DeserializationEPSS 0.5%CVE-2024-53262LOWUnescaped error message included on error page in SvelteKitEPSS 0.5%CVE-2026-42567MEDIUMSvelte: ReDoS in `<svelte:element>` Tag ValidationEPSS 0.4%CVE-2026-82256MEDIUMSvelteKit before 2.69.1 Denial of Service via Remote FormEPSS 0.4%