CVE-2026-40073
Under certain circumstances, requests could bypass the BODYSIZELIMIT on SvelteKit applications running with adapter-node. This bypass does not affect body size limits at other layers of the application stack, so limits enforced in the WAF, gateway, or at the platform level are unaffected.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/sveltejs/kit/security/advisories/GHSA-2crg-3p73-43xp, https://nvd.nist.gov/vuln/detail/CVE-2026-40073, https://github.com/sveltejs/kit/commit/3202ed6c98f9e8d86bf0c4c7ad0f2e273e5e3b95, https://github.com/sveltejs/kit, https://github.com/sveltejs/kit/releases/tag/%40sveltejs%2Fkit%402.57.1, https://github.com/sveltejs/kit/releases/tag/@sveltejs/kit@2.57.1
