GHSA-29g2-3rmr-qm68: Medium severity npm/@sveltejs/kit vulnerability
Impact SvelteKit is vulnerable to remote CPU-exhaustion DoS attacks via specifically-crafted Accept headers. The impact is mitigated by default header length limits on most platforms, but in the case of raised or absent limits a denial of service is possible.
Patches The vulnerability is patched in @sveltejs/kit version 2.70.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@sveltejs/kitto a version that resolves this vulnerability.Fixed in 2.70.2 - Upgrade
Upgrade
@sveltejs/kitto a version that resolves this vulnerability.Fixed in 2.70.2
Event History
Frequently Asked Questions
What is the severity of GHSA-29g2-3rmr-qm68?
The severity of GHSA-29g2-3rmr-qm68 is rated as medium with a score of 5.3.
What impact does GHSA-29g2-3rmr-qm68 have on applications?
GHSA-29g2-3rmr-qm68 allows for remote CPU-exhaustion DoS attacks through specifically-crafted Accept headers.
How do I fix GHSA-29g2-3rmr-qm68?
To fix GHSA-29g2-3rmr-qm68, you should update to the patched version of the SvelteKit library.
Is there a way to mitigate GHSA-29g2-3rmr-qm68?
Mitigation for GHSA-29g2-3rmr-qm68 is possible by enforcing default header length limits on your application.
What software is affected by GHSA-29g2-3rmr-qm68?
GHSA-29g2-3rmr-qm68 affects the npm package @sveltejs/kit.