Home

Description

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Prior to 1.4.26 , t.String({ format: 'url' }) is vulnerable to ReDoS. Repeating a partial url format (protocol and hostname) multiple times cause regex to slow down significantly. This vulnerability is fixed in 1.4.26.

PUBLISHED Reserved 2026-03-05 | Published 2026-03-10 | Updated 2026-03-11 | Assigner GitHub_M




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-1333: Inefficient Regular Expression Complexity

Product status

< 1.4.26
affected

References

github.com/...elysia/security/advisories/GHSA-f45g-68q3-5w8x

github.com/EdamAme-x/elysia-poc-redos

cve.org (CVE-2026-30837)

nvd.nist.gov (CVE-2026-30837)

Download JSON