Live data from GitHub and npm, updated daily.
Data last fetched: 2026-08-24
10 active CVEs reported via OSV.dev
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
SvelteKit vulnerable to Cross-Site Request Forgery
@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
CPU exhaustion in SvelteKit remote form deserialization (experimental only)
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
Sending a GET or HEAD request with a body crashes SvelteKit
SvelteKit framework has Insufficient CSRF protection for CORS requests
Get SLA-backed support, security patches, and direct access to senior engineers for SvelteKit — without relying on volunteer maintainers.