TGViewer
Computer Science and Programming Computer Science and Programming @computer_science_and_programming · 140K subscribers
Post #2075 11.4K
CVEs affecting the Svelte ecosystem
The Svelte team has released patches for 5 security vulnerabilities across devalue, svelte, @sveltejs/kit, and @sveltejs/adapter-node. The vulnerabilities include two DoS issues in devalue.parse causing memory/CPU exhaustion, a memory amplification DoS in SvelteKit's remote functions deserializer, a DoS and potential SSRF when using prerendering, and an XSS vulnerability via the hydratable feature. Users should upgrade to devalue 5.6.2, svelte 5.46.4, @sveltejs/kit 2.49.5, and @sveltejs/adapter-node 5.5.1. Most vulnerabilities affect applications parsing user-controlled input or using specific experimental features.
  • 👍 9
  • ❤ 5
  • 🔥 1
More from @computer_science_and_programming
  1. Oct 3, 2026BYD says it will have a solid-state car next year, the earliest date anyone has given BYD…
  2. Oct 1, 2026Introducing G#: A Go-like language for .NET G# is a new open-source, Go-inspired programmi…
  3. Sep 30, 2026Chrome for Developers Chrome 146 introduces three notable features for web developers. Scr…
  4. Sep 26, 2026Introduction to Solon A comprehensive tutorial walks through building a REST API with Solo…
  5. Sep 25, 2026The strangler fig pattern: modernizing without a big-bang rewrite A detailed guide to the…
  6. Sep 24, 2026Lessons From Four Years of Writing a Weekly Newsletter A .NET blogger reflects on four yea…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →