A critical cache deception vulnerability (CVE-2026-27118) was discovered in SvelteKit apps deployed on Vercel. The SvelteKit Vercel adapter's `__pathname` query parameter — intended for Incremental Static Regeneration — allows any request path to be overridden without restriction. By crafting a URL under the `/_app/immutable/`

9m read timeFrom aikido.dev
Post cover image
Table of contents
Quick SummaryDiscoveryCache Poisoning?Cache Deception!The aftermathKey TakeawaysFix statusTimeline

Sort: