vulns.co
/
GKData.io MCP

zhero_web_security · 1 min read

SvelteKit: origin construction and routing must preserve server request authority

Research on CVE-2025-67647 describes framework-internal routing consuming an origin derived from insufficiently trusted request metadata. The researcher demonstrates server-side response retrieval and process termination from unhandled network errors. The maintainer limits internal-service exposure to services reachable without authentication from the runtime; downstream cache effects depend on deployment behavior.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

Trace which component authoritatively establishes the application origin, and contain failures in internal network operations. The maintainer lists SvelteKit 2.49.5 and adapter-node 5.5.1 as patched. Fixed-origin configuration and reverse-proxy host validation address origin trust, but do not substitute for patching the broader availability issue.

Before reading

  • Server-side rendering and framework integration concepts
  • Basic trust-boundary and secure-input review

Context and limits

  • The maintainer requires a prerendered route. SSRF additionally requires adapter-node without a configured origin and without reverse-proxy host validation. The advisory distinguishes the broader DoS case starting at SvelteKit 2.44.0 from the origin-dependent case starting at 2.19.0.
  • The article provides demonstrations, not evidence of an actual third-party production compromise. Cache-related browser impact is conditional, not universal.
  • The article displays January 2026 without a day; January 15 is its separately stated patch/advisory date. Learning prerequisites are editorial.

Sources and provenance

  1. Avoiding the paradox: A native full-read SSRF and one-shot DoS in SvelteKit zhero_web_security · reviewed 2026-10-03
  2. Denial of service and possible SSRF when using prerendering Svelte · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software