CVE-2026-30837
EUVD-2026-1086010.03.2026, 21:16
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Prior to 1.4.26 , t.String({ format: 'url' }) is vulnerable to ReDoS. Repeating a partial url format (protocol and hostname) multiple times cause regex to slow down significantly. This vulnerability is fixed in 1.4.26.EnginsightAffected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elysiajs | elysia | 𝑥 < 1.4.26 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration