Memory exhaustion in SvelteKit remote form deserialization (experimental only)
Description
Published to the GitHub Advisory Database
Feb 19, 2026
Reviewed
Feb 19, 2026
Last updated
Feb 19, 2026
Versions of
@sveltejs/kitprior to 2.52.2 with remote functions enabled can be vulnerable to memory exhaustion. Malformed form data can cause the server process to crash due to excessive memory allocation, resulting in denial of service.Only applications using both
experimental.remoteFunctionsandformare vulnerable.References