GHSA-g5m6-hxpp-fc49

    Dashboard / Vulnerabilities / GHSA-g5m6-hxpp-fc49

    GHSA-g5m6-hxpp-fc49

    Published: 24 Jan 2024Last Modified: 10 Sept 2026

    Summary: Sending a GET or HEAD request with a body crashes SvelteKit

    Details: ### Summary In SvelteKit 2 sending a GET request with a body eg `{}` to a SvelteKit app in preview or with `adapter-node` throws `Request with GET/HEAD method cannot have body.` and crashes the app. ``` node:internal/deps/undici/undici:6066 throw new TypeError("Request with GET/HEAD method cannot have body."); ^ TypeError: Request with GET/HEAD method cannot have body. at new Request (node:internal/deps/undici/undici:6066:17) at getRequest (file:///C:/Users/admin/Desktop/reproduction/node_modules/@sveltejs/kit/src/exports/node/index.js:107:9) at file:///C:/Users/admin/Desktop/reproduction/node_modules/@sveltejs/kit/src/exports/vite/preview/index.js:181:26 at call (file:///C:/Users/admin/Desktop/reproduction/node_modules/vite/dist/node/chunks/dep-9A4-l-43.js:44795:7) at next (file:///C:/Users/admin/Desktop/reproduction/node_modules/vite/dist/node/chunks/dep-9A4-l-43.js:44739:5) at file:///C:/Users/admin/Desktop/reproduction/node_modules/@sveltejs/kit/src/exports/vite/preview/index.js:172:6 at call (file:///C:/Users/admin/Desktop/reproduction/node_modules/vite/dist/node/chunks/dep-9A4-l-43.js:44795:7) at next (file:///C:/Users/admin/Desktop/reproduction/node_modules/vite/dist/node/chunks/dep-9A4-l-43.js:44739:5) at file:///C:/Users/admin/Desktop/reproduction/node_modules/@sveltejs/kit/src/exports/vite/preview/index.js:211:27 at call (file:///C:/Users/admin/Desktop/reproduction/node_modules/vite/dist/node/chunks/dep-9A4-l-43.js:44795:7) Node.js v20.11.0 ``` `TRACE` requests will also cause the app to crash. Prerendered pages and SvelteKit 1 apps are not affected. <!-- ### Details _Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._ --> ### PoC <!-- _Complete instructions, including specific configuration details, to reproduce the vulnerability._ --> First do a fresh install of SvelteKit 2 with the example app. Typescript. 1. `npm run build` 2. `npm run preview` 3. Go to http://localhost:4173 (works) 4. curl -X GET -d "{}" http://localhost:4173/bye 5. Application crashes and http://localhost:4173 is down ### Impact <!-- _What kind of vulnerability is it? Who is impacted?_ --> Denial of Service for apps using `adapter-node`

    Affected packages

    Package

    Name: @sveltejs/kit

    Purl: pkg:npm/%40sveltejs/kit

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 2.0.0
    Fixed -2.4.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-g5m6-hxpp-fc49 | CVE-DB