<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T13:39:43.874955+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275521</id>
    <title>EUVD-2026-275521</title>
    <updated>2026-10-08T13:39:46.244065+00:00</updated>
    <content>EUVD-2026-275521</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30837</id>
    <title>fkie_cve-2026-30837</title>
    <updated>2026-10-08T13:39:46.244143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Prior to 1.4.26 , t.String({ format: 'url' }) is vulnerable to ReDoS. Repeating a partial url format (protocol and hostname) multiple times cause regex to slow down significantly. This vulnerability is fixed in 1.4.26.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-30837"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f45g-68q3-5w8x</id>
    <title>GHSA-f45g-68q3-5w8x — Elysia has a string URL format ReDoS</title>
    <updated>2026-10-08T13:39:46.244193+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: elysia</p>
<p>### Impact
`t.String({ format: 'url' })` is vulnerable to redos</p>
<p>Repeating a partial url format (protocol and hostname) multiple times cause regex to slow down significantly
```js
'http://a'.repeat(n)
```</p>
<p>Here's a table demonstrating how long it takes to process repeated partial url format
| `n` repeat | elapsed_ms |
| --- | --- |
| 1024 | 33.993 |
| 2048 | 134.357 |
| 4096 | 537.608 |
| 8192 | 2155.842 |
| 16384 | 8618.457 |
| 32768 | 34604.139 |</p>
<p>### Patches
Patched by 1.4.26, please kindly update `elysia` to &gt;= 1.4.26</p>
<p>Here's how long it takes after the patch
| `n` repeat | elapsed_ms |
| --- | --- |
| 1024 | 0.194 |
| 2048 | 0.274 |
| 4096 | 0.455 |
| 8192 | 0.831 |
| 16384 | 1.632 |
| 32768 | 3.052 |</p>
<p>### Workarounds
1. It's recommended to always limit URL format to a reasonable length
```ts
t.String({
	format: 'url',
	maxLength: 288
})
```</p>
<p>2. If a long URL format is necessary, to patch this without updating to 1.4.26, add the following code to any part of your codebase
```js
import { FormatRegistry } from '@sinclair/typebox'</p>
<p>FormatRegistry.Delete('url')
FormatRegistry.Set('url', (value) =&gt;
	/^(?:https?|ftp):\/\/(?:[^\s:@]+(?::[^\s@]*)?@)?(?:(?!(?:10|127)(?:\.\d{1,3}){3})(?!(?:169\.254|192\.168)(?:\.\d{1,3}){2})(?!172\.(?:1[6-9]|2\d|3[0-1])(?:\.\d{1,3}){2})(?:[1-9]\d?|1\d\d|2[01]\d|22[0-3])(?:\.(?:1?\d{1,2}|2[0-4]\d|25[0-5])){2}(?:\.(?:[1-9]\d?|1\d\d|2[0-4]\d|25[0-4]))|(?:(?:[a-z0-9\u{00a1}-\u{ffff}]+-)*[a-z0-9\u{00a1}-\u{ffff}]+)(?:\.(?:[a-z0-9\u{00a1}-\u{ffff}]+-)…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f45g-68q3-5w8x"/>
  </entry>
</feed>
