CVE 8.2 HIGH

SvelteKit has a BODY_SIZE_LIMIT bypass in @sveltejs/adapter-node_CVE-2026-40073

8.2 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Description

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under certain circumstances, requests could bypass the BODY_SIZE_LIMIT on SvelteKit applications running with adapter-node. This bypass does not affect body size limits at other layers of the application stack, so limits enforced in the WAF, gateway, or at the platform level are unaffected. This vulnerability is fixed in 2.57.1.

Basic Information

ID CVE-2026-40073
Source GitHub_M
Published Apr 10, 2026 at 16:24

Affected Product

Vendor sveltejs
Product kit
Version < 2.57.1
Affected Versions sveltejs kit < 2.57.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.