Vulnerabilities/

SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering

Severity:
High

Description

Versions of SvelteKit are vulnerable to a server side request forgery (SSRF) and denial of service (DoS) under certain conditions.

Recommendation

Update the @sveltejs/kit package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@sveltejs/kit
Anything's wrong? Let us know Last updated on January 15, 2026