Package compatibility

SvelteKit 1.0

What Node.js versions does this SvelteKit version support?

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Declared Node.js requirement

engines.node
>=16.14
Tip version
1.0.0
Source
npm Registry (engines.node)

Node.js compatibility matrix

Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.

Other SvelteKit lines

Security

Advisories affecting SvelteKit 1.0 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
9
Known exploited
0
Highest CVSS
  • CVE-2026-66062GHSA-29g2-3rmr-qm68

    SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header

    Affected:
    <2.70.2
    Fixed in:
    2.70.2
    Source:
    OSV source
  • CVE-2026-82257GHSA-866w-xmhq-wj7x

    SvelteKit: Prototype pollution in file input deletion path in remote-function forms

    Affected:
    <2.69.1
    Fixed in:
    2.69.1
    Source:
    OSV source
  • CVE-2026-82256GHSA-wqjv-9729-c5q2

    SvelteKit: Big remote form function payloads can cause Node process to crash

    Affected:
    <2.69.1
    Fixed in:
    2.69.1
    Source:
    OSV source
  • CVE-2026-40074GHSA-3f6h-2hrp-w5wx

    @sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service

    Affected:
    <2.57.1
    Fixed in:
    2.57.1
    Source:
    OSV source · Advisory
  • CVE-2026-40073GHSA-2crg-3p73-43xp

    @sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass

    Affected:
    <2.57.1
    Fixed in:
    2.57.1
    Source:
    OSV source · Advisory
  • CVE-2024-53261GHSA-rjjv-87mx-6x3h

    @sveltejs/kit vulnerable to XSS on dev mode 404 page

    Affected:
    <2.8.3
    Fixed in:
    2.8.3
    Source:
    OSV source · Advisory
  • CVE-2024-53262GHSA-mh2x-fcqh-fmqv

    @sveltejs/kit has unescaped error message included on error page

    Affected:
    <2.8.3
    Fixed in:
    2.8.3
    Source:
    OSV source · Advisory
  • CVE-2023-29008GHSA-gv7g-x59x-wf8f

    SvelteKit framework has Insufficient CSRF protection for CORS requests

    Affected:
    <1.15.2
    Fixed in:
    1.15.2
    Source:
    OSV source · Advisory
  • CVE-2023-29003GHSA-5p75-vc5g-8rv2

    SvelteKit vulnerable to Cross-Site Request Forgery

    Affected:
    <1.15.1
    Fixed in:
    1.15.1
    Source:
    OSV source · Advisory