Skip to content

v1.19.4

Latest

Choose a tag to compare

@edmundhung edmundhung released this 07 Jun 10:35
· 14 commits to main since this release

Security

Fixed a denial-of-service vulnerability in the future parseSubmission API, imported from @conform-to/react/future, where submissions with many repeated fields could cause excessive FormData processing.

Users who parse untrusted server-side form submissions with parseSubmission from @conform-to/react/future should upgrade to 1.19.4.

See GHSA-525m-7f82-2mf7 for details.

Full Changelog: v1.19.3...v1.19.4