Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-15
10 active CVEs reported via OSV.dev
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
SvelteKit vulnerable to Cross-Site Request Forgery
@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params
CPU exhaustion in SvelteKit remote form deserialization (experimental only)
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
Sending a GET or HEAD request with a body crashes SvelteKit
SvelteKit framework has Insufficient CSRF protection for CORS requests
@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
Get SLA-backed support, security patches, and direct access to senior engineers for SvelteKit — without relying on volunteer maintainers.
Talk to an Expert →