CVE-2026-49250Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-03: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-03: 107-03
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - Conform @conform-to/dom CPU Exhaustion in parseSubmission (CVE-2026-49250) Conform's parseSubmission future API parsed FormData / URLSearchParams by looking up values by field name, requiring repeated scans of the submitted entries. An attacker who sends a crafted submission with many unique field names can force excessive synchronous CPU work - an algorithmic-complexity denial of service that can hang the handling process. The flaw is remotely exploitable with no authentication and no user interaction, and any endpoint that passes untrusted form submissions to Conform is exposed. The fix iterates submitted entries directly instead of repeatedly looking up values by name. 👉Upgrade @conform-to/dom to 1.19.4.

    Post summary

    The post announces a high‑severity CVE‑2026‑49250 that causes CPU exhaustion via form submissions, provides technical details, and includes a patch recommendation but no evidence of active exploitation or PoC.

    0000076
    236 followersView on X

Explore more