CVE-2024-32866: Edmundhung Conform

High severity, CVSS 8.6. EPSS: 0.7% chance of exploitation in the next 30 days.

Conform, a type-safe form validation library, allows the parsing of nested objects in the form of `object.property`. Due to an improper implementation of this feature in versions prior to 1.1.1, an attacker can exploit the feature to trigger prototype pollution by passing a crafted input to `parseWith...` functions. Applications that use conform for server-side validation of form data or URL parameters are affected by this vulnerability. Version 1.1.1 contains a patch for the issue.

Affected products

  • Edmundhung Conform: before 1.1.1 (fixed in 1.1.1); any version

Published 2024-04-23. Last modified 2026-06-17.