{"id":"GHSA-9643-4qgh-g8mx","summary":"elysia has Inefficient Algorithmic Complexity and Interpretation Conflict","details":"Elysia v1.4.28 is vulnerable to denial-of-service attacks due to CPU exhaustion in the form data normalization code.\n\nElysia uses `getAll` to retrieve value from FormData. It is called directly relative to the total number of key-value pairs in the form data. The total amount of work the for loop has to do grows quadratically, so doubling the number of unique key-value pairs quadruples the amount of work. In the above PoC, each .getAll call scans through all of the `n` key-value pairs in the form data. Because there are `n` unique keys in the form data, there are .getAll calls, so in total the form data normalizer has to scan `n` x `n` key-value pairs.\n\n### Impact\nEndpoints using `multipart/form-data`\n\n### Patches\n1.4.29\n\n### Workarounds\nno 100% confirm workaround beside updating the patch","aliases":["CVE-2026-56669"],"modified":"2026-09-23T22:00:04.429969872Z","published":"2026-09-23T21:54:50Z","database_specific":{"nvd_published_at":"2026-07-08T21:16:50Z","cwe_ids":["CWE-407","CWE-436"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-23T21:54:50Z"},"references":[{"type":"WEB","url":"https://github.com/elysiajs/elysia/security/advisories/GHSA-9643-4qgh-g8mx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56669"},{"type":"WEB","url":"https://github.com/elysiajs/elysia/commit/8358ff9efbcedf9534995f5977f26b9ceab59329"},{"type":"WEB","url":"https://gist.github.com/jviide/ea040eabe7bac058326174e2cd42dfd9"},{"type":"PACKAGE","url":"https://github.com/elysiajs/elysia"},{"type":"WEB","url":"https://github.com/elysiajs/elysia/releases/tag/1.4.29"}],"affected":[{"package":{"name":"elysia","ecosystem":"npm","purl":"pkg:npm/elysia"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.4.29"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9643-4qgh-g8mx/GHSA-9643-4qgh-g8mx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}