OVERVIEW CVE-2026-40073 affects SvelteKit versions prior to 2.57.1, specifically applications using the adapter-node deployment configuration. The vulnerability allows attackers to bypass the BODY_SIZE_LIMIT protection mechanism, which is designed to restrict incoming request payload sizes. This bypass is isolated to SvelteKit's internal handling and does not compromise security controls implemented at higher layers such as WAF, gateway, or platform-level protections. SEVERITY The vulnerability carries a CVSS v3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack has low complexity and represents a denial-of-service risk through availability impact, as oversized requests could consume excessive resources and degrade application performance. The FAUCET Risk Score of 48.0/100 indicates moderate risk, though the extremely low EPSS score of 0.000830 suggests limited real-world exploitation probability. EXPLOITATION STATUS The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and shows no active exploitation activity. It does not appear on the Hot List, indicating minimal community attention or public exploit code availability. Organizations should prioritize upgrading to SvelteKit 2.57.1 or later as a standard maintenance practice rather than an emergency response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.57.1CPE matchmatch criteria | cpe:2.3:a:svelte:kit:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.