CVE-2026-56669: elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
Elysia v1.4.28 is vulnerable to denial-of-service attacks due to CPU exhaustion in the form data normalization code. Elysia uses `getAll` to retrieve value from FormData. It is called directly relative to the total number of key-value pairs in the form data. The total amount of work the for loop has to do grows quadratically, so doubling the number of unique key-value pairs quadruples the amount of work. In the above PoC, each .getAll call scans through all of the `n` key-value pairs in the form data. Because there are `n` unique keys in the form data, there are .getAll calls, so in total the form data normalizer has to scan `n` x `n` key-value pairs. ### Impact Endpoints using `multipart/form-data` ### Patches 1.4.29 ### Workarounds no 100% confirm workaround beside updating the patch
Recommended action
Recommended action
Upgrade affected packages to a patched version: elysia 1.4.29.
Technical details
- Vendor
- Not specified
- Product
- elysia
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source