@sveltejs/kit
10 known vulnerabilities · 0 critical · 2 high
Memory exhaustion in SvelteKit remote form deserialization (experimental only)
SvelteKit framework has Insufficient CSRF protection for CORS requests
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
CPU exhaustion in SvelteKit remote form deserialization (experimental only)
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)
@sveltejs/kit: `query.batch` cross-talk