Impact
Conform is a type‑safe form validation library that allows the parsing of nested objects in the form of object.property. From version 1.8.0 through 1.19.4, the parseSubmission future API in packages/conform-dom/formdata.ts repeatedly scans FormData or URLSearchParams entries by each unique field name. An unauthenticated attacker can submit a crafted form containing many unique names, causing excessive synchronous CPU work and leading to a denial of service. The vulnerability is a form data size overflow, represented by CWE-407.
Affected Systems
The vulnerability affects the Conform library, versions 1.8.0-1.19.4, distributed by edmundhung on GitHub. It was fixed in release 1.19.4, which removes the vulnerable scanning loop. Applications that integrate Conform should verify their installed version matches or exceeds the fixed release.
Risk and Exploitability
The CVSS score of 8.7 classifies the flaw as high severity. The EPSS score of < 1% indicates an unauthenticated attacker can submit a crafted payload without additional privileges to consume excessive CPU cycles and cause a denial of service. Because the denial of service can affect the entire application, the risk is significant for exposed services that rely on Conform for request processing. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Github GHSA