Vulnerability library
Security checkJuly 02, 2026

@conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpm@conform-to/dom

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A CPU exhaustion vulnerability exists in Conform’s parseSubmission future API when parsing FormData or URLSearchParams submissions with many unique field names.

Recommendation

Update the @conform-to/dom package to the latest compatible version. Followings are version details:

  • Affected version(s): >= 1.8.0, < 1.19.4
  • Patched version(s): 1.19.4

References

Could your website be exposed too?

SmartScanner can check your website for @conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 02, 2026