CVE-2026-27118
Last modified
CVE-2026-27118 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Versions of @sveltejs/adapter-vercel prior to 6.3.2 are vulnerable to cache poisoning. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Versions of @sveltejs/adapter-vercel prior to 6.3.2 are vulnerable to cache poisoning. An internal query parameter intended for Incremental Static Regeneration (ISR) is accessible on all routes, allowing an attacker to cause sensitive user-specific responses to be cached and served to other users. Successful exploitation requires a victim to visit an attacker-controlled link while authenticated. Existing deployments are protected by Vercel's WAF, but users should upgrade as soon as possible. This vulnerability is fixed in 6.3.2.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-27118?
How severe is CVE-2026-27118?
How do I fix CVE-2026-27118?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-27112Kargo manages and automates the promotion of software artifa…9.9
- CVE-2026-27113Liquid Prompt is an adaptive prompt for Bash and Zsh. Starti…6.3
- CVE-2026-27114NanaZip is an open source file archive. Starting in version …7.5
- CVE-2026-27115ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9…7.1
- CVE-2026-27116Vikunja is an open-source self-hosted task management platfo…6.1
- CVE-2026-27117bit7z is a cross-platform C++ static library that allows the…7.5
- CVE-2026-27119svelte performance oriented web framework. From 5.39.3, <=5.…5.4
- CVE-2026-2712The WP-Optimize plugin for WordPress is vulnerable to unauth…5.4
- CVE-2026-27120Leafkit is a templating language with Swift-inspired syntax.…6.1
- CVE-2026-27121svelte performance oriented web framework. Versions of svelt…5.4
- CVE-2026-27122svelte performance oriented web framework. Prior to 5.51.5, …5.4
- CVE-2026-27123Rejected reason: Reason: This candidate was issued in error.
Are you affected by CVE-2026-27118?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
