top of page
perceptive_background_267k.jpg

SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an appl…

Published:

28 August 2026 at 00:00:00

Alert date:

28 August 2026 at 22:01:47

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

SvelteKit versions 2.49.0 through 2.53.2 contain a deserialization expansion vulnerability in the experimental form remote function. When applications enable experimental.remoteFunctions and use the form function to process file arrays without proper validation, attackers can exploit this flaw by submitting small inputs that expand into very large file arrays. This leads to excessive processing overhead and potential denial of service conditions. The vulnerability specifically affects the files.length and individual file size validation logic. A fix has been released in SvelteKit version 2.53.3. The issue is classified as a deserialization expansion or 'zip bomb'-style attack vector targeting file upload handling. Developers using the experimental remote functions feature should upgrade immediately to mitigate risk.

Technical details

Mitigation steps:

Affected products:

SvelteKit 2.49.0 through 2.53.2

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page