Vulnerabilities
Vulnerable Software
Elysiajs:  >> Elysia  >> 1.4.21  Security Vulnerabilities
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server communication. Prior to version 1.4.27, an Elysia cookie can be overridden by prototype pollution , eg. `__proto__`. This issue is patched in 1.4.27. As a workaround, use t.Cookie validation to enforce validation value and/or prevent iterable over cookie if possible.
CVSS Score
6.5
EPSS Score
0.0
Published
2026-03-18
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Prior to 1.4.26 , t.String({ format: 'url' }) is vulnerable to ReDoS. Repeating a partial url format (protocol and hostname) multiple times cause regex to slow down significantly. This vulnerability is fixed in 1.4.26.
CVSS Score
7.5
EPSS Score
0.0
Published
2026-03-10


Contact Us

Shodan ® - All rights reserved