CVE-2026-30837
HIGHElysia <1.4.26 - DoS
Title source: llmDescription
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Prior to 1.4.26 , t.String({ format: 'url' }) is vulnerable to ReDoS. Repeating a partial url format (protocol and hostname) multiple times cause regex to slow down significantly. This vulnerability is fixed in 1.4.26.
Scores
CVSS v3
7.5
EPSS
0.0003
EPSS Percentile
7.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-1333
Status
published
Products (1)
elysiajs/elysia
< 1.4.26
Published
Mar 10, 2026
Tracked Since
Mar 11, 2026