{"id":"GHSA-f45g-68q3-5w8x","summary":"Elysia has a string URL format ReDoS","details":"### Impact\n`t.String({ format: 'url' })` is vulnerable to redos\n\nRepeating a partial url format (protocol and hostname) multiple times cause regex to slow down significantly\n```js\n'http://a'.repeat(n)\n```\n\nHere's a table demonstrating how long it takes to process repeated partial url format\n| `n` repeat | elapsed_ms |\n| --- | --- |\n| 1024 | 33.993 |\n| 2048 | 134.357 |\n| 4096 | 537.608 |\n| 8192 | 2155.842 |\n| 16384 | 8618.457 |\n| 32768 | 34604.139 |\n\n### Patches\nPatched by 1.4.26, please kindly update `elysia` to \u003e= 1.4.26 \n\nHere's how long it takes after the patch\n| `n` repeat | elapsed_ms |\n| --- | --- |\n| 1024 | 0.194 |\n| 2048 | 0.274 |\n| 4096 | 0.455 |\n| 8192 | 0.831 |\n| 16384 | 1.632 |\n| 32768 | 3.052 |\n\n### Workarounds\n1. It's recommended to always limit URL format to a reasonable length\n```ts\nt.String({\n\tformat: 'url',\n\tmaxLength: 288\n})\n```\n\n2. If a long URL format is necessary, to patch this without updating to 1.4.26, add the following code to any part of your codebase\n```js\nimport { FormatRegistry } from '@sinclair/typebox'\n\nFormatRegistry.Delete('url')\nFormatRegistry.Set('url', (value) =\u003e\n\t/^(?:https?|ftp):\\/\\/(?:[^\\s:@]+(?::[^\\s@]*)?@)?(?:(?!(?:10|127)(?:\\.\\d{1,3}){3})(?!(?:169\\.254|192\\.168)(?:\\.\\d{1,3}){2})(?!172\\.(?:1[6-9]|2\\d|3[0-1])(?:\\.\\d{1,3}){2})(?:[1-9]\\d?|1\\d\\d|2[01]\\d|22[0-3])(?:\\.(?:1?\\d{1,2}|2[0-4]\\d|25[0-5])){2}(?:\\.(?:[1-9]\\d?|1\\d\\d|2[0-4]\\d|25[0-4]))|(?:(?:[a-z0-9\\u{00a1}-\\u{ffff}]+-)*[a-z0-9\\u{00a1}-\\u{ffff}]+)(?:\\.(?:[a-z0-9\\u{00a1}-\\u{ffff}]+-)*[a-z0-9\\u{00a1}-\\u{ffff}]+)*(?:\\.(?:[a-z\\u{00a1}-\\u{ffff}]{2,})))(?::\\d{2,5})?(?:\\/[^\\s]*)?$/iu.test(\n\t\tvalue\n\t)\n)\n```","aliases":["CVE-2026-30837"],"modified":"2026-03-13T04:22:10.994103Z","published":"2026-03-10T21:04:25Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-10T21:04:25Z","nvd_published_at":"2026-03-10T21:16:47Z","cwe_ids":["CWE-1333"]},"references":[{"type":"WEB","url":"https://github.com/elysiajs/elysia/security/advisories/GHSA-f45g-68q3-5w8x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30837"},{"type":"WEB","url":"https://github.com/EdamAme-x/elysia-poc-redos"},{"type":"PACKAGE","url":"https://github.com/elysiajs/elysia"}],"affected":[{"package":{"name":"elysia","ecosystem":"npm","purl":"pkg:npm/elysia"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.4.26"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-f45g-68q3-5w8x/GHSA-f45g-68q3-5w8x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}