@sveltejs/kit is vulnerable to Denial of Service
53
Medium Risk
SvelteKit processes remote form function payloads server-side, and a large or malformed payload can trigger a promise rejection that is never caught. The unhandled promise rejection propagates and terminates the Node.js process. An unauthenticated attacker can repeatedly send such payloads to crash the server and cause a denial of service. The fix adds catch handling so these rejections no longer take down the process.
You are affected if you are using a version that falls within the vulnerable range and you use remote form functions.
@sveltejs/kit is vulnerable to Denial of Service in versions 2.49.0 - 2.69.0.
Upgrade the @sveltejs/kit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant