{"id":"CVE-2026-82258","aliases":["GHSA-hgv7-v322-mmgr"],"url":"https://o3.security/vulnerability/CVE-2026-82258","summary":"SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batch","details":"SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploit specific timing conditions to access sensitive data from other users' concurrent requests.","published":"2026-08-28T10:49:42.085Z","modified":"2026-09-02T03:47:32.274439181Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"@sveltejs/kit","fixedVersion":"2.60.1"}],"fix":{"url":"https://github.com/sveltejs/kit/commit/dadaefc2e647a0a62f49f3ee8bc7aa46f5e27056","label":"sveltejs/kit@dadaefc"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82258.json"},{"type":"ADVISORY","url":"https://github.com/sveltejs/kit/security/advisories/GHSA-hgv7-v322-mmgr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82258"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/sveltekit-2.38.0-before-2.60.1-cross-user-data-disclosure-via-query-batch"},{"type":"WEB","url":"https://github.com/sveltejs/kit/commit/dadaefc2e647a0a62f49f3ee8bc7aa46f5e27056"},{"type":"PACKAGE","url":"https://github.com/sveltejs/kit"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-02T03:47:32.274439181Z"}}