Description
Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From 1.8.0 until 1.19.4, the parseSubmission future API in packages/conform-dom/formdata.ts repeatedly scans FormData or URLSearchParams entries by each unique field name. An unauthenticated attacker can submit a crafted form containing many unique names, causing excessive synchronous CPU work and denial of service in an application that passes the submission to parseSubmission. Applications should continue to enforce request parsing limits before invoking Conform. This issue is fixed in version 1.19.4.
Published: 2026-09-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

Conform is a type‑safe form validation library that allows the parsing of nested objects in the form of object.property. From version 1.8.0 through 1.19.4, the parseSubmission future API in packages/conform-dom/formdata.ts repeatedly scans FormData or URLSearchParams entries by each unique field name. An unauthenticated attacker can submit a crafted form containing many unique names, causing excessive synchronous CPU work and leading to a denial of service. The vulnerability is a form data size overflow, represented by CWE-407.

Affected Systems

The vulnerability affects the Conform library, versions 1.8.0-1.19.4, distributed by edmundhung on GitHub. It was fixed in release 1.19.4, which removes the vulnerable scanning loop. Applications that integrate Conform should verify their installed version matches or exceeds the fixed release.

Risk and Exploitability

The CVSS score of 8.7 classifies the flaw as high severity. The EPSS score of < 1% indicates an unauthenticated attacker can submit a crafted payload without additional privileges to consume excessive CPU cycles and cause a denial of service. Because the denial of service can affect the entire application, the risk is significant for exposed services that rely on Conform for request processing. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 20, 2026 at 23:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Conform to version 1.19.4 or later, where the issue is fixed.
  • Enforce request parsing limits (e.g., maximum number of form fields) before invoking Conform’s parseSubmission to prevent CPU exhaustion.
  • Validate or restrict the number of unique form field names submitted, rejecting requests that exceed a safe threshold.

Generated by OpenCVE AI on September 20, 2026 at 23:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-525m-7f82-2mf7 @conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields
History

Tue, 15 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Edmundhung
Edmundhung conform
Vendors & Products Edmundhung
Edmundhung conform

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From 1.8.0 until 1.19.4, the parseSubmission future API in packages/conform-dom/formdata.ts repeatedly scans FormData or URLSearchParams entries by each unique field name. An unauthenticated attacker can submit a crafted form containing many unique names, causing excessive synchronous CPU work and denial of service in an application that passes the submission to parseSubmission. Applications should continue to enforce request parsing limits before invoking Conform. This issue is fixed in version 1.19.4.
Title Conform: parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields
Weaknesses CWE-407
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Edmundhung Conform
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T19:01:26.926Z

Reserved: 2026-05-28T14:33:01.178Z

Link: CVE-2026-49250

cve-icon Vulnrichment

Updated: 2026-09-14T19:01:21.958Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:49.360

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-49250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:00:08Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity