CPU exhaustion in SvelteKit remote form deserialization (experimental only)
Description
Published to the GitHub Advisory Database
Feb 19, 2026
Reviewed
Feb 19, 2026
Last updated
Feb 19, 2026
Versions of
@sveltejs/kitprior to 2.52.2 with remote functions enabled are vulnerable to CPU exhaustion. Malformed form data can cause the server to become unresponsive while processing a request, resulting in denial of service.Only applications using both
experimental.remoteFunctionsandformare vulnerable.References