What is CVE-2026-66062?
CVE-2026-66062 is a ReDoS vulnerability in the content negotiation header parser of SvelteKit versions prior to 2.70.2, allowing quadratic backtracking via headers like 'Accept'. A remote attacker can cause server resource exhaustion with a crafted request. Immediate upgrade to SvelteKit 2.70.2 or later is strongly recommended.
Azərbaycanca: CVE-2026-66062 SvelteKit-in 2.70.2-dən əvvəlki versiyalarında "Accept" kimi başlıqları analiz edən "content negotiation" parser-də ReDoS (Regular Expression Denial of Service) zəifliyidir. Uzaqdan hücumçu xüsusi hazırlanmış sorğu ilə server resurslarını yükləyə bilər. SvelteKit-i dərhal 2.70.2 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which component of SvelteKit is affected by CVE-2026-66062?
This vulnerability affects the content negotiation parser of SvelteKit, which parses headers such as 'Accept'.
Which version should be upgraded to in order to mitigate CVE-2026-66062?
To mitigate the vulnerability, an immediate upgrade to SvelteKit version 2.70.2 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.