PT-2026-24422 · Elysia · Elysia

Edamame-X

·

Publicado

2026-03-10

·

Atualizado

2026-03-10

·

CVE-2026-30837

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Elysia versions prior to 1.4.26
Description Elysia, a Typescript framework used for request validation, type inference, OpenAPI documentation, and client-server communication, contains a Regular Expression Denial of Service (ReDoS) issue. Specifically, the t.String({ format: 'url' }) function is susceptible to significant slowdowns when provided with a repeated partial URL format (protocol and hostname). This occurs because the regular expression used for URL validation becomes inefficient when processing such input.
Recommendations Update to version 1.4.26 or later.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-30837
GHSA-F45G-68Q3-5W8X

Produtos afetados

Elysia