PT-2026-24422 · Elysia · Elysia
Edamame-X
·
Published
2026-03-10
·
Updated
2026-03-10
·
CVE-2026-30837
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Elysia versions prior to 1.4.26
Description
Elysia, a Typescript framework used for request validation, type inference, OpenAPI documentation, and client-server communication, contains a Regular Expression Denial of Service (ReDoS) issue. Specifically, the
t.String({ format: 'url' }) function is susceptible to significant slowdowns when provided with a repeated partial URL format (protocol and hostname). This occurs because the regular expression used for URL validation becomes inefficient when processing such input.Recommendations
Update to version 1.4.26 or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elysia