@conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields
- Severity:
- High
Description
A CPU exhaustion vulnerability exists in Conform’s parseSubmission future API when parsing FormData or URLSearchParams submissions with many unique field names.
Recommendation
Update the @conform-to/dom package to the latest compatible version. Followings are version details:
- Affected version(s): >= 1.8.0, < 1.19.4
- Patched version(s): 1.19.4
References
Related Issues
- devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse - CVE-2026-22775
- js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals - CVE-2026-49293
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
- Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parse - CVE-2026-22774
You might also like:
- Tags:
- npm
- @conform-to/dom
Anything's wrong? Let us know Last updated on July 02, 2026


