# CVE-2026-30837

## Summary

- **CVE ID:** CVE-2026-30837
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-1333
- **Published:** Mar 10, 2026
- **Last Modified:** Mar 11, 2026

## Description

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Prior to 1.4.26 , t.String({ format: 'url' }) is vulnerable to ReDoS. Repeating a partial url format (protocol and hostname) multiple times cause regex to slow down significantly. This vulnerability is fixed in 1.4.26.

## Affected Products

- elysiajs — elysia (< 1.4.26)

## References

- [CNA](https://github.com/elysiajs/elysia/security/advisories/GHSA-f45g-68q3-5w8x)
- [CNA](https://github.com/EdamAme-x/elysia-poc-redos)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.49%
- **EPSS Percentile:** 40.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._