PT-2026-31989 · Sveltekit+1 · Sveltekit+1

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-40073

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SvelteKit versions prior to 2.57.1
Description SvelteKit, a framework for building web applications, had a potential issue where requests could bypass the BODY SIZE LIMIT when using the adapter-node. This bypass did not impact body size limits enforced by other security measures like Web Application Firewalls (WAFs) or platform-level restrictions.
Recommendations Update to SvelteKit version 2.57.1 or later.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40073
GHSA-2CRG-3P73-43XP

Affected Products

Sveltekit
Adapter-Node