Package compatibility
SvelteKit
Node.js requirements from npm Registry (engines.node) for the @sveltejs/kit package. This is not a lifecycle software page.
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Version lines
Each line reflects a declared engines.node tip. Requirement changes across tips appear as separate lines when present.
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- CVE-2026-66062GHSA-29g2-3rmr-qm68
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
- Affected:
- <2.70.2
- Fixed in:
- 2.70.2
- Source:
- OSV source
- CVE-2026-82257GHSA-866w-xmhq-wj7x
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
- Affected:
- <2.69.1
- Fixed in:
- 2.69.1
- Source:
- OSV source
- CVE-2026-82256GHSA-wqjv-9729-c5q2
SvelteKit: Big remote form function payloads can cause Node process to crash
- Affected:
- <2.69.1
- Fixed in:
- 2.69.1
- Source:
- OSV source
- CVE-2026-82258GHSA-hgv7-v322-mmgr
@sveltejs/kit: `query.batch` cross-talk
- Affected:
- >=2.38.0,<2.60.1
- Fixed in:
- 2.60.1
- Source:
- OSV source
- CVE-2026-40074GHSA-3f6h-2hrp-w5wx
@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
- Affected:
- <2.57.1
- Fixed in:
- 2.57.1
- Source:
- OSV source · Advisory
- CVE-2026-40073GHSA-2crg-3p73-43xp
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
- Affected:
- <2.57.1
- Fixed in:
- 2.57.1
- Source:
- OSV source · Advisory
- CVE-2026-82259GHSA-fpg4-jhqr-589c
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
- Affected:
- >=2.49.0,<2.53.3
- Fixed in:
- 2.53.3
- Source:
- OSV source
- GHSA-88qp-p4qg-rqm6
CPU exhaustion in SvelteKit remote form deserialization (experimental only)
- Affected:
- >=2.49.0,<2.52.2
- Fixed in:
- 2.52.2
- Source:
- OSV source
- GHSA-vrhm-gvg7-fpcf
Memory exhaustion in SvelteKit remote form deserialization (experimental only)
- Affected:
- >=2.49.0,<2.52.2
- Fixed in:
- 2.52.2
- Source:
- OSV source
- CVE-2026-22803GHSA-j2f3-wq62-6q46
@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)
- Affected:
- >=2.49.0,<2.49.5
- Fixed in:
- 2.49.5
- Source:
- OSV source · Advisory
- CVE-2025-67647GHSA-j62c-4x62-9r35
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
- Affected:
- >=2.19.0,<2.49.5
- Fixed in:
- 2.49.5
- Source:
- OSV source · Advisory
- CVE-2025-32388GHSA-6q87-84jw-cjhp
@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params
- Affected:
- >=2.0.0,<2.20.6
- Fixed in:
- 2.20.6
- Source:
- OSV source · Advisory
