PT-2026-31990 · Sveltekit · Sveltekit

CVE-2026-40074

·

Published

2026-04-10

·

Updated

2026-04-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SvelteKit versions prior to 2.57.1
Description SvelteKit, a framework for developing web applications, is susceptible to a denial-of-service (DoS) condition. When the redirect function is invoked within the handle server hook with a location parameter containing characters invalid for an HTTP header, an unhandled TypeError occurs. This is particularly problematic when the location parameter passed to redirect includes unsanitized user input, potentially leading to DoS on certain platforms.
Recommendations Update to SvelteKit version 2.57.1 or later.

Exploit

Fix

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40074
GHSA-3F6H-2HRP-W5WX

Affected Products

Sveltekit