Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42567

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}></svelte:element>. This issue has been patched in version 5.55.7.

A flaw was found in Svelte, a web framework. An internal regular expression (regex) in the Svelte runtime, specifically when processing <svelte:element this={tag}></svelte:element>, can be exploited by a remote attacker. By providing specially crafted input, an attacker can cause the regex to take an exponential amount of time to process, leading to a Regular Expression Denial of Service (ReDoS) condition. This can make the affected application unresponsive or unavailable to legitimate users.

Отчет

A flaw was found in Svelte. An internal regex in the Svelte runtime can take exponential time when processing specially crafted input in <svelte:element this={tag}> elements, leading to a Regular Expression Denial of Service (ReDoS). Red Hat products that ship svelte (Podman Desktop, Konflux) use it as a UI framework and do not expose user-controlled input to the vulnerable regex path in production.

Меры по смягчению последствий

Upgrade to Svelte 5.55.7 or later.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Podman Desktoprh-podman-desktop.gitFix deferred
Red Hat Build of Podman Desktop - Tech Previewrhdesktop/rh-podman-desktop-ext-bootc-rhel10Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2487114svelte: Svelte: Regular Expression Denial of Service (ReDoS)

EPSS

Процентиль: 35%
0.00421
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}></svelte:element>. This issue has been patched in version 5.55.7.

github
3 месяца назад

Svelte: ReDoS in `<svelte:element>` Tag Validation

EPSS

Процентиль: 35%
0.00421
Низкий

5.9 Medium

CVSS3