{"id":"GHSA-2crg-3p73-43xp","summary":"@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass","details":"Under certain circumstances, requests could bypass the `BODY_SIZE_LIMIT` on SvelteKit applications running with `adapter-node`. This bypass does not affect body size limits at other layers of the application stack, so limits enforced in the WAF, gateway, or at the platform level are unaffected.","aliases":["CVE-2026-40073"],"modified":"2026-04-10T20:04:59.545849Z","published":"2026-04-10T17:24:31Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-04-10T17:24:31Z","nvd_published_at":"2026-04-10T17:17:12Z","cwe_ids":["CWE-770"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/sveltejs/kit/security/advisories/GHSA-2crg-3p73-43xp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40073"},{"type":"WEB","url":"https://github.com/sveltejs/kit/commit/3202ed6c98f9e8d86bf0c4c7ad0f2e273e5e3b95"},{"type":"PACKAGE","url":"https://github.com/sveltejs/kit"},{"type":"WEB","url":"https://github.com/sveltejs/kit/releases/tag/%40sveltejs%2Fkit%402.57.1"},{"type":"WEB","url":"https://github.com/sveltejs/kit/releases/tag/@sveltejs/kit@2.57.1"}],"affected":[{"package":{"name":"@sveltejs/kit","ecosystem":"npm","purl":"pkg:npm/%40sveltejs/kit"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.57.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.57.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-2crg-3p73-43xp/GHSA-2crg-3p73-43xp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}