{"api_version":"v1","generated_at":"2026-10-07T19:10:00+00:00","product":{"cve_count":18,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-sveltejs-kit-dc07e496c01d","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/kit","name":"kit","next_cursor":null,"observations":[{"affected":"2.49.0 < 2.52.1","affected_versions_present":true,"cve_id":"CVE-2026-82261","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82261","fixed":"2.52.1","last_modified":"2026-08-28T14:41:04.001Z","patch_url":"https://github.com/sveltejs/kit/security/advisories/GHSA-88qp-p4qg-rqm6","primary_source":"","published":"2026-08-28T10:49:44.323Z"},{"affected":"2.49.0 < 2.52.1","affected_versions_present":true,"cve_id":"CVE-2026-82260","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82260","fixed":"2.52.1","last_modified":"2026-08-28T15:52:30.481Z","patch_url":"https://github.com/sveltejs/kit/security/advisories/GHSA-vrhm-gvg7-fpcf","primary_source":"","published":"2026-08-28T10:49:43.651Z"},{"affected":"2.49.0 < 2.53.3","affected_versions_present":true,"cve_id":"CVE-2026-82259","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82259","fixed":"2.53.3","last_modified":"2026-08-28T13:51:52.024Z","patch_url":"https://github.com/sveltejs/kit/security/advisories/GHSA-fpg4-jhqr-589c","primary_source":"","published":"2026-08-28T10:49:42.969Z"},{"affected":"kit: 2.38.0 < 2.60.1","affected_versions_present":true,"cve_id":"CVE-2026-82258","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82258","fixed":"kit: 2.60.1","last_modified":"2026-08-31T18:36:22.058Z","patch_url":"https://github.com/sveltejs/kit/security/advisories/GHSA-hgv7-v322-mmgr","primary_source":"","published":"2026-08-28T10:49:42.085Z"},{"affected":"< 2.69.1","affected_versions_present":true,"cve_id":"CVE-2026-82257","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82257","fixed":"2.69.1","last_modified":"2026-08-28T13:58:28.653Z","patch_url":"https://github.com/sveltejs/kit/security/advisories/GHSA-866w-xmhq-wj7x","primary_source":"","published":"2026-08-28T10:49:41.355Z"},{"affected":"< 2.69.1","affected_versions_present":true,"cve_id":"CVE-2026-82256","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82256","fixed":"2.69.1","last_modified":"2026-08-28T14:41:47.444Z","patch_url":"https://github.com/sveltejs/kit/security/advisories/GHSA-wqjv-9729-c5q2","primary_source":"","published":"2026-08-28T10:49:40.634Z"},{"affected":"< 2.70.2","affected_versions_present":true,"cve_id":"CVE-2026-66062","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-66062","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T21:02:12.997Z","patch_url":"","primary_source":"","published":"2026-08-07T16:49:43.853Z"},{"affected":"< 2.57.1","affected_versions_present":true,"cve_id":"CVE-2026-40074","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40074","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-14T14:17:29.422Z","patch_url":"https://github.com/sveltejs/kit/commit/10d7b44425c3d9da642eecce373d0c6ef83b4fcd","primary_source":"","published":"2026-04-10T16:26:07.068Z"},{"affected":"< 2.57.1","affected_versions_present":true,"cve_id":"CVE-2026-40073","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40073","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-13T15:36:57.412Z","patch_url":"https://github.com/sveltejs/kit/commit/3202ed6c98f9e8d86bf0c4c7ad0f2e273e5e3b95","primary_source":"","published":"2026-04-10T16:24:39.987Z"},{"affected":"< 6.3.2","affected_versions_present":true,"cve_id":"CVE-2026-27118","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27118","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-24T18:42:11.028Z","patch_url":"","primary_source":"","published":"2026-02-20T21:24:55.577Z"},{"affected":">= 2.49.0, < 2.49.5","affected_versions_present":true,"cve_id":"CVE-2026-22803","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22803","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-15T19:06:13.528Z","patch_url":"https://github.com/sveltejs/kit/commit/8ed8155215b9a74012fecffb942ad9a793b274e5","primary_source":"","published":"2026-01-15T18:37:57.831Z"},{"affected":">= 2.19.0, < 2.49.5","affected_versions_present":true,"cve_id":"CVE-2025-67647","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-67647","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-15T18:58:01.975Z","patch_url":"https://github.com/sveltejs/kit/commit/d9ae9b00b14f5574d109f3fd548f960594346226","primary_source":"","published":"2026-01-15T18:33:25.295Z"},{"affected":">= 2.0.0, < 2.20.6","affected_versions_present":true,"cve_id":"CVE-2025-32388","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32388","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-16T13:33:47.383Z","patch_url":"","primary_source":"","published":"2025-04-15T22:32:06.059Z"},{"affected":"< 2.8.3","affected_versions_present":true,"cve_id":"CVE-2024-53261","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-53261","fixed":"2.8.3","last_modified":"2024-11-25T20:04:36.967Z","patch_url":"https://github.com/sveltejs/kit/commit/d338d4635a7fd947ba5112df6ee632c4a0979438","primary_source":"","published":"2024-11-25T19:15:28.233Z"},{"affected":"< 2.8.3","affected_versions_present":true,"cve_id":"CVE-2024-53262","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-53262","fixed":"2.8.3","last_modified":"2024-11-25T20:24:05.750Z","patch_url":"https://github.com/sveltejs/kit/commit/134e36343ef57ed7e6e2b3bb9e7f05ad37865794","primary_source":"","published":"2024-11-25T19:07:20.317Z"},{"affected":">= 2.0.0, < 2.4.3; >= 2.0.0, < 2.1.2; >= 3.0.0, < 3.0.3; = 4.0.0","affected_versions_present":true,"cve_id":"CVE-2024-23641","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-23641","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-11-13T15:09:39.781Z","patch_url":"https://github.com/sveltejs/kit/commit/af34142631c876a7eb62ff81f71e8a3f90dafee9","primary_source":"","published":"2024-01-24T16:56:32.392Z"},{"affected":"< 1.15.2","affected_versions_present":true,"cve_id":"CVE-2023-29008","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-29008","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-10T16:26:25.826Z","patch_url":"https://github.com/sveltejs/kit/commit/ba436c6685e751d968a960fbda65f24cf7a82e9f","primary_source":"","published":"2023-04-06T16:36:50.972Z"},{"affected":"< 1.15.1","affected_versions_present":true,"cve_id":"CVE-2023-29003","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-29003","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-10T21:29:13.609Z","patch_url":"https://github.com/sveltejs/kit/commit/bb2253d51d00aba2e4353952d4fb0dcde6c77123","primary_source":"","published":"2023-04-04T21:20:43.983Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"sveltejs"}}
