Svelte Regular Expression Denial-of-Service Vulnerability in Element Tag Validation

Vulnerability

A denial-of-service vulnerability has been identified in the Svelte web framework, specifically in versions 5.51.5 prior to 5.55.7. The issue arises from an internal regular expression in the Svelte runtime that can cause exponential time complexity when processing tags of unconstrained length within the `<svelte:element>` tag. This vulnerability can lead to significant performance degradation. However, applications that restrict tag lengths or allow only a predetermined list of tags are not affected.

Impact

Exploitation of this vulnerability can cause a denial-of-service condition, leading to high availability impact by causing the application to become unresponsive or slow.

Remediation

Users can upgrade to Svelte version 5.55.7, where this vulnerability has been patched.

Added: Jun 9, 2026, 8:18 PM
Updated: Jun 9, 2026, 8:18 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
2.5
exploitability
4.7
remediation
7.9
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.