SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82258

MEDIUM · CVSS 4.8 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

SvelteKit versions from 2.38.0 to 2.60.1 are vulnerable to a race condition in the query.batch function, which can allow attackers to exploit timing issues and access sensitive data from concurrent user requests. This vulnerability poses a risk to applications utilizing these versions, particularly those handling sensitive user information. Developers and security teams using affected SvelteKit versions should prioritize patching to mitigate potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82258
Severity
MEDIUM
CVSS
4.8
EPSS
0.15%

Original NVD Description

SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploit specific timing conditions to access sensitive data from other users' concurrent requests.

Related CVEs

Other vulnerabilities affecting the same vendor(s)