VDB
Sign up
HIGH7.5

GHSA-9643-4qgh-g8mx

elysia has Inefficient Algorithmic Complexity and Interpretation Conflict

Quick fix

GHSA-9643-4qgh-g8mx — elysia: upgrade to the fixed version with the command below.

npm install elysia@1.4.29

Details

Elysia v1.4.28 is vulnerable to denial-of-service attacks due to CPU exhaustion in the form data normalization code.

Elysia uses `getAll` to retrieve value from FormData. It is called directly relative to the total number of key-value pairs in the form data. The total amount of work the for loop has to do grows quadratically, so doubling the number of unique key-value pairs quadruples the amount of work. In the above PoC, each .getAll call scans through all of the `n` key-value pairs in the form data. Because there are `n` unique keys in the form data, there are .getAll calls, so in total the form data normalizer has to scan `n` x `n` key-value pairs.

### Impact Endpoints using `multipart/form-data`

### Patches 1.4.29

### Workarounds no 100% confirm workaround beside updating the patch

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/elysia
Introduced in: 0Fixed in: 1.4.29
Fixnpm install elysia@1.4.29

References