
🚨High - Conform @conform-to/dom CPU Exhaustion in parseSubmission (CVE-2026-49250) Conform's parseSubmission future API parsed FormData / URLSearchParams by looking up values by field name, requiring repeated scans of the submitted entries. An attacker who sends a crafted submission with many unique field names can force excessive synchronous CPU work - an algorithmic-complexity denial of service that can hang the handling process. The flaw is remotely exploitable with no authentication and no user interaction, and any endpoint that passes untrusted form submissions to Conform is exposed. The fix iterates submitted entries directly instead of repeatedly looking up values by name. 👉Upgrade @conform-to/dom to 1.19.4.
Post summary
The post announces a high‑severity CVE‑2026‑49250 that causes CPU exhaustion via form submissions, provides technical details, and includes a patch recommendation but no evidence of active exploitation or PoC.
