Description
Versions of SvelteKit are vulnerable to a server side request forgery (SSRF) and denial of service (DoS) under certain conditions.
Recommendation
Update the @sveltejs/kit package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.19.0, <= 2.49.4
- Patched version(s): 2.49.5
References
Could your website be exposed too?
SmartScanner can check your website for SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering and gives you actionable findings to investigate.
Start a free scanRelated Issues
- axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL - CVE-2025-27152
- youtube-regex vulnerable to Regex Denial of Service - CVE-2025-65122
- SvelteKit vulnerable to Cross-Site Request Forgery - CVE-2023-29003
- is_js vulnerable to Regular Expression Denial of Service - CVE-2020-26302
You might also like:
See something that needs correcting? Let us knowUpdated January 15, 2026


