๐Ÿ” CVE Alert

CVE-2026-40073

UNKNOWN 0.0

SvelteKit has a BODY_SIZE_LIMIT bypass in @sveltejs/adapter-node

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
12th

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under certain circumstances, requests could bypass the BODY_SIZE_LIMIT on SvelteKit applications running with adapter-node. This bypass does not affect body size limits at other layers of the application stack, so limits enforced in the WAF, gateway, or at the platform level are unaffected. This vulnerability is fixed in 2.57.1.

CWE CWE-770
Vendor sveltejs
Product kit
Published Apr 10, 2026
Last Updated Apr 13, 2026
Stay Ahead of the Next One

Get instant alerts for sveltejs kit

Be the first to know when new unknown vulnerabilities affecting sveltejs kit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

sveltejs / kit
< 2.57.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sveltejs/kit/security/advisories/GHSA-2crg-3p73-43xp github.com: https://github.com/sveltejs/kit/commit/3202ed6c98f9e8d86bf0c4c7ad0f2e273e5e3b95 github.com: https://github.com/sveltejs/kit/releases/tag/@sveltejs/[email protected]