Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40073

25
FAUCET Score

OVERVIEW CVE-2026-40073 affects SvelteKit versions prior to 2.57.1, specifically applications using the adapter-node deployment configuration. The vulnerability allows attackers to bypass the BODY_SIZE_LIMIT protection mechanism, which is designed to restrict incoming request payload sizes. This bypass is isolated to SvelteKit's internal handling and does not compromise security controls implemented at higher layers such as WAF, gateway, or platform-level protections. SEVERITY The vulnerability carries a CVSS v3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack has low complexity and represents a denial-of-service risk through availability impact, as oversized requests could consume excessive resources and degrade application performance. The FAUCET Risk Score of 48.0/100 indicates moderate risk, though the extremely low EPSS score of 0.000830 suggests limited real-world exploitation probability. EXPLOITATION STATUS The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and shows no active exploitation activity. It does not appear on the Hot List, indicating minimal community attention or public exploit code availability. Organizations should prioritize upgrading to SvelteKit 2.57.1 or later as a standard maintenance practice rather than an emergency response.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.57.1CPE matchmatch criteria
cpe:2.3:a:svelte:kit:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.2HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.54%
Probability of exploitation in next 30 days
EPSS Percentile
42.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0054 is in the 20th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: @sveltejs/kitFixed in: 2.57.1

Vendor Advisories (1)

npmGHSA-2crg-3p73-43xphigh

@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass

Apr 10, 2026

References

github.com / sveltejs/kit/commit/3202ed6c98f9e8d86bf0c4c7ad0f2e273e5e3b95
Patch
github.com / sveltejs/kit/releases/tag/@sveltejs/[email protected]
ProductRelease Notes
github.com / sveltejs/kit/security/advisories/GHSA-2crg-3p73-43xp
Vendor Advisory