{"id":"CVE-2026-66062","aliases":["GHSA-29g2-3rmr-qm68"],"url":"https://o3.security/vulnerability/CVE-2026-66062","summary":"SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header","details":"SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the content negotiation header parser used by SvelteKit's request handling (for headers such as Accept) uses a regular expression vulnerable to quadratic backtracking, so a maliciously crafted header value can cause excessive CPU consumption and degrade or deny service. Version 2.70.2 fixes the issue.","published":"2026-08-07T16:49:43.853Z","modified":"2026-09-11T03:30:22.567288772Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":{"score":0.00291,"percentile":0.21711,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@sveltejs/kit","fixedVersion":"2.70.2"}],"fix":{"url":"https://github.com/sveltejs/kit/commit/82712fc02c24b1dcf5b25d7a52129cd8455f04f5","label":"sveltejs/kit@82712fc"},"references":[{"type":"WEB","url":"https://github.com/sveltejs/kit/releases/tag/@sveltejs/kit@2.70.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66062.json"},{"type":"ADVISORY","url":"https://github.com/sveltejs/kit/security/advisories/GHSA-29g2-3rmr-qm68"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66062"},{"type":"FIX","url":"https://github.com/sveltejs/kit/commit/82712fc02c24b1dcf5b25d7a52129cd8455f04f5"},{"type":"PACKAGE","url":"https://github.com/sveltejs/kit"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-11T03:30:22.567288772Z"}}