Package compatibility

SvelteKit

Node.js requirements from npm Registry (engines.node) for the @sveltejs/kit package. This is not a lifecycle software page.

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Version lines

Each line reflects a declared engines.node tip. Requirement changes across tips appear as separate lines when present.

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

  • CVE-2026-66062GHSA-29g2-3rmr-qm68

    SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header

    Affected:
    <2.70.2
    Fixed in:
    2.70.2
    Source:
    OSV source
  • CVE-2026-82257GHSA-866w-xmhq-wj7x

    SvelteKit: Prototype pollution in file input deletion path in remote-function forms

    Affected:
    <2.69.1
    Fixed in:
    2.69.1
    Source:
    OSV source
  • CVE-2026-82256GHSA-wqjv-9729-c5q2

    SvelteKit: Big remote form function payloads can cause Node process to crash

    Affected:
    <2.69.1
    Fixed in:
    2.69.1
    Source:
    OSV source
  • CVE-2026-82258GHSA-hgv7-v322-mmgr

    @sveltejs/kit: `query.batch` cross-talk

    Affected:
    >=2.38.0,<2.60.1
    Fixed in:
    2.60.1
    Source:
    OSV source
  • CVE-2026-40074GHSA-3f6h-2hrp-w5wx

    @sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service

    Affected:
    <2.57.1
    Fixed in:
    2.57.1
    Source:
    OSV source · Advisory
  • CVE-2026-40073GHSA-2crg-3p73-43xp

    @sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass

    Affected:
    <2.57.1
    Fixed in:
    2.57.1
    Source:
    OSV source · Advisory
  • CVE-2026-82259GHSA-fpg4-jhqr-589c

    SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)

    Affected:
    >=2.49.0,<2.53.3
    Fixed in:
    2.53.3
    Source:
    OSV source
  • GHSA-88qp-p4qg-rqm6

    CPU exhaustion in SvelteKit remote form deserialization (experimental only)

    Affected:
    >=2.49.0,<2.52.2
    Fixed in:
    2.52.2
    Source:
    OSV source
  • GHSA-vrhm-gvg7-fpcf

    Memory exhaustion in SvelteKit remote form deserialization (experimental only)

    Affected:
    >=2.49.0,<2.52.2
    Fixed in:
    2.52.2
    Source:
    OSV source
  • CVE-2026-22803GHSA-j2f3-wq62-6q46

    @sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)

    Affected:
    >=2.49.0,<2.49.5
    Fixed in:
    2.49.5
    Source:
    OSV source · Advisory
  • CVE-2025-67647GHSA-j62c-4x62-9r35

    SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering

    Affected:
    >=2.19.0,<2.49.5
    Fixed in:
    2.49.5
    Source:
    OSV source · Advisory
  • CVE-2025-32388GHSA-6q87-84jw-cjhp

    @sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params

    Affected:
    >=2.0.0,<2.20.6
    Fixed in:
    2.20.6
    Source:
    OSV source · Advisory