PT-2026-24422 · Elysia · Elysia

Edamame-X

·

Published

2026-03-10

·

Updated

2026-03-10

·

CVE-2026-30837

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Elysia versions prior to 1.4.26
Description Elysia, a Typescript framework used for request validation, type inference, OpenAPI documentation, and client-server communication, contains a Regular Expression Denial of Service (ReDoS) issue. Specifically, the t.String({ format: 'url' }) function is susceptible to significant slowdowns when provided with a repeated partial URL format (protocol and hostname). This occurs because the regular expression used for URL validation becomes inefficient when processing such input.
Recommendations Update to version 1.4.26 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30837
GHSA-F45G-68Q3-5W8X

Affected Products

Elysia