Versions of @sveltejs/kit prior to 2.52.2 with remote functions enabled are vulnerable to CPU exhaustion. Malformed form data can cause the server to become unresponsive while processing a request, resulting in denial of service.
Only applications using both experimental.remoteFunctions and form are vulnerable.
{
"github_reviewed": true,
"github_reviewed_at": "2026-02-19T20:30:25Z",
"cwe_ids": [
"CWE-843"
],
"severity": "MODERATE",
"nvd_published_at": null
}