VYPR
High severityNVD Advisory· Published Mar 10, 2026· Updated Mar 11, 2026

Elysia has a string URL format redos

CVE-2026-30837

Description

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Prior to 1.4.26 , t.String({ format: 'url' }) is vulnerable to ReDoS. Repeating a partial url format (protocol and hostname) multiple times cause regex to slow down significantly. This vulnerability is fixed in 1.4.26.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
elysianpm
< 1.4.261.4.26

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.