{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aelysiajselysianode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:elysiajs:elysia:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-56669"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Elysia (\u003c 1.4.29)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","web-framework"],"_cs_type":"advisory","_cs_vendors":["Elysia"],"content_html":"\u003cp\u003eElysia versions prior to 1.4.29 contain an algorithmic complexity vulnerability (CVE-2026-56669) within the framework's \u003ccode\u003emultipart/form-data\u003c/code\u003e normalization logic. When the framework processes incoming form data, the internal \u003ccode\u003egetAll\u003c/code\u003e method used to retrieve values operates with quadratic time complexity relative to the number of key-value pairs provided. Specifically, for each unique key in the form data, the normalization process scans all existing key-value pairs. Consequently, an attacker can craft a malicious multipart request containing a large number of unique keys, forcing the application to perform n-squared operations. This results in significant CPU consumption, potentially leading to a denial-of-service state for the affected application endpoint. The issue is resolved in version 1.4.29, which optimizes the data retrieval process to prevent the identified CPU exhaustion.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability directly impacts web applications and API endpoints built using the Elysia framework that accept \u003ccode\u003emultipart/form-data\u003c/code\u003e uploads. Successful exploitation allows an unauthenticated attacker to cause excessive CPU utilization on the server, potentially rendering the service unresponsive to legitimate users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Elysia dependency to version 1.4.29 or later immediately to incorporate the algorithmic fix for CVE-2026-56669.\u003c/li\u003e\n\u003cli\u003eAudit existing infrastructure to identify internet-facing endpoints processing multipart form data.\u003c/li\u003e\n\u003cli\u003eImplement request size and complexity limits at the web application firewall (WAF) or load balancer level to mitigate potential resource exhaustion attacks while the patching process is completed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T01:57:02Z","date_published":"2026-09-24T01:57:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-elysia-dos/","summary":"Elysia versions before 1.4.29 are vulnerable to a denial-of-service attack due to quadratic time complexity in the 'multipart/form-data' normalization process, leading to CPU exhaustion.","title":"Denial of Service in Elysia via Algorithmic Complexity","url":"https://feed.craftedsignal.io/briefs/2026-09-elysia-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:elysiajs:elysia:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}