How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Security Update: Multiple vulnerabilities in SvelteKit

calendar_today January 14, 2026 person domain netlify

The Svelte team has disclosed five CVEs affecting the Svelte and SvelteKit ecosystem. Here’s what Netlify customers need to know. Vulnerabilities CVE-2026-22775 : Memory/CPU exhaustion in devalue (5.1.0–5.6.1) CVE-2026-22774 : Memory exhaustion in devalue (5.3.0–5.6.1) CVE-2026-22803 : Server crash in @sveltejs/kit (2.49.0–2.49.4) CVE-2025-67647 : Server crash and SSRF in @sveltejs/kit (2.44.0–2.49.4) and @sveltejs/adapter-node (2.19.0–2.49.4) CVE-2025-15265 : XSS in svelte (5.46.0–5.46.3) Impact on Netlify CVE-2026-22775, CVE-2026-22774, and CVE-2026-22803 These are server-side…

open_in_new Read original post