📦 Kit

by Svelte

🔍 What is Kit?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-67647

CRITICAL CVSS 9.1 Jan 15, 2026

SvelteKit versions 2.19.0 through 2.49.4 are vulnerable to server-side request forgery (SSRF) and denial of service (DoS) attacks. The vulnerability affects applications with prerendered routes, parti...

CVE-2026-22803

HIGH CVSS 7.5 Jan 15, 2026

CVE-2026-22803 is a denial-of-service vulnerability in SvelteKit's experimental form remote function that allows attackers to cause memory exhaustion by sending specially-crafted binary payloads. This...

CVE-2024-23641

HIGH CVSS 7.5 Jan 24, 2024

SvelteKit 2 applications crash when receiving GET or TRACE requests with a body, requiring manual restart. This affects SvelteKit 2 apps in preview or production hosting, but not prerendered pages or ...