Elliott Johnson
8 exploits
Active since Jan 2026
Svelte devalue: DoS via sparse array deserialization
CVSS 7.5
SvelteKit <2.57.1 adapter-node - BODY_SIZE_LIMIT Bypass
CVSS 7.5
SvelteKit's invalidated redirect in handle hook causes Denial-of-Service
CVSS 7.5
Svelte 5.53.0-5.53.5 - Cross-Site Scripting via transformError HTML Injection
CVSS 5.4
svelte < 5.51.5 - Prototype Pollution in Server-Side Rendering Attribute Spreading
CVSS 6.8
Svelte devalue 5.3.0-5.6.1 - Denial of Service via Typed Array Hydration
CVSS 7.5
Svelte devalue 5.1.0-5.6.1 - Denial of Service via Malformed ArrayBuffer Input
CVSS 7.5
SvelteKit 2.49.0-2.49.4 - Denial of Service via Form Remote Function Memory Exhaustion
CVSS 7.5