<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 21:43:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275521</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275521</link>
      <description>EUVD-2026-275521</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275521</guid>
    </item>
    <item>
      <title>fkie_cve-2026-30837</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30837</link>
      <description>&lt;p&gt;Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Prior to 1.4.26 , t.String({ format: &amp;#39;url&amp;#39; }) is vulnerable to ReDoS. Repeating a partial url format (protocol and hostname) multiple times cause regex to slow down significantly. This vulnerability is fixed in 1.4.26.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Prior to 1.4.26 , t.String({ format: &amp;#39;url&amp;#39; }) is vulnerable to ReDoS. Repeating a partial url format (protocol and hostname) multiple times cause regex to slow down significantly. This vulnerability is fixed in 1.4.26.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-30837</guid>
    </item>
    <item>
      <title>GHSA-f45g-68q3-5w8x — Elysia has a string URL format ReDoS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f45g-68q3-5w8x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: elysia&lt;/p&gt;
&lt;p&gt;### Impact
`t.String({ format: &amp;#39;url&amp;#39; })` is vulnerable to redos&lt;/p&gt;
&lt;p&gt;Repeating a partial url format (protocol and hostname) multiple times cause regex to slow down significantly
```js
&amp;#39;http://a&amp;#39;.repeat(n)
```&lt;/p&gt;
&lt;p&gt;Here&amp;#39;s a table demonstrating how long it takes to process repeated partial url format
| `n` repeat | elapsed_ms |
| --- | --- |
| 1024 | 33.993 |
| 2048 | 134.357 |
| 4096 | 537.608 |
| 8192 | 2155.842 |
| 16384 | 8618.457 |
| 32768 | 34604.139 |&lt;/p&gt;
&lt;p&gt;### Patches
Patched by 1.4.26, please kindly update `elysia` to &amp;gt;= 1.4.26&lt;/p&gt;
&lt;p&gt;Here&amp;#39;s how long it takes after the patch
| `n` repeat | elapsed_ms |
| --- | --- |
| 1024 | 0.194 |
| 2048 | 0.274 |
| 4096 | 0.455 |
| 8192 | 0.831 |
| 16384 | 1.632 |
| 32768 | 3.052 |&lt;/p&gt;
&lt;p&gt;### Workarounds
1. It&amp;#39;s recommended to always limit URL format to a reasonable length
```ts
t.String({
	format: &amp;#39;url&amp;#39;,
	maxLength: 288
})
```&lt;/p&gt;
&lt;p&gt;2. If a long URL format is necessary, to patch this without updating to 1.4.26, add the following code to any part of your codebase
```js
import { FormatRegistry } from &amp;#39;@sinclair/typebox&amp;#39;&lt;/p&gt;
&lt;p&gt;FormatRegistry.Delete(&amp;#39;url&amp;#39;)
FormatRegistry.Set(&amp;#39;url&amp;#39;, (value) =&amp;gt;
	/^(?:https?|ftp):\/\/(?:[^\s:@]+(?::[^\s@]*)?@)?(?:(?!(?:10|127)(?:\.\d{1,3}){3})(?!(?:169\.254|192\.168)(?:\.\d{1,3}){2})(?!172\.(?:1[6-9]|2\d|3[0-1])(?:\.\d{1,3}){2})(?:[1-9]\d?|1\d\d|2[01]\d|22[0-3])(?:\.(?:1?\d{1,2}|2[0-4]\d|25[0-5])){2}(?:\.(?:[1-9]\d?|1\d\d|2[0-4]\d|25[0-4]))|(?:(?:[a-z0-9\u{00a1}-\u{ffff}]+-)*[a-z0-9\u{00a1}-\u{ffff}]+)(?:\.(?:[a-z0-9\u{00a1}-\u{ffff}]+-)…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: elysia&lt;/p&gt;
&lt;p&gt;### Impact
`t.String({ format: &amp;#39;url&amp;#39; })` is vulnerable to redos&lt;/p&gt;
&lt;p&gt;Repeating a partial url format (protocol and hostname) multiple times cause regex to slow down significantly
```js
&amp;#39;http://a&amp;#39;.repeat(n)
```&lt;/p&gt;
&lt;p&gt;Here&amp;#39;s a table demonstrating how long it takes to process repeated partial url format
| `n` repeat | elapsed_ms |
| --- | --- |
| 1024 | 33.993 |
| 2048 | 134.357 |
| 4096 | 537.608 |
| 8192 | 2155.842 |
| 16384 | 8618.457 |
| 32768 | 34604.139 |&lt;/p&gt;
&lt;p&gt;### Patches
Patched by 1.4.26, please kindly update `elysia` to &amp;gt;= 1.4.26&lt;/p&gt;
&lt;p&gt;Here&amp;#39;s how long it takes after the patch
| `n` repeat | elapsed_ms |
| --- | --- |
| 1024 | 0.194 |
| 2048 | 0.274 |
| 4096 | 0.455 |
| 8192 | 0.831 |
| 16384 | 1.632 |
| 32768 | 3.052 |&lt;/p&gt;
&lt;p&gt;### Workarounds
1. It&amp;#39;s recommended to always limit URL format to a reasonable length
```ts
t.String({
	format: &amp;#39;url&amp;#39;,
	maxLength: 288
})
```&lt;/p&gt;
&lt;p&gt;2. If a long URL format is necessary, to patch this without updating to 1.4.26, add the following code to any part of your codebase
```js
import { FormatRegistry } from &amp;#39;@sinclair/typebox&amp;#39;&lt;/p&gt;
&lt;p&gt;FormatRegistry.Delete(&amp;#39;url&amp;#39;)
FormatRegistry.Set(&amp;#39;url&amp;#39;, (value) =&amp;gt;
	/^(?:https?|ftp):\/\/(?:[^\s:@]+(?::[^\s@]*)?@)?(?:(?!(?:10|127)(?:\.\d{1,3}){3})(?!(?:169\.254|192\.168)(?:\.\d{1,3}){2})(?!172\.(?:1[6-9]|2\d|3[0-1])(?:\.\d{1,3}){2})(?:[1-9]\d?|1\d\d|2[01]\d|22[0-3])(?:\.(?:1?\d{1,2}|2[0-4]\d|25[0-5])){2}(?:\.(?:[1-9]\d?|1\d\d|2[0-4]\d|25[0-4]))|(?:(?:[a-z0-9\u{00a1}-\u{ffff}]+-)*[a-z0-9\u{00a1}-\u{ffff}]+)(?:\.(?:[a-z0-9\u{00a1}-\u{ffff}]+-)…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f45g-68q3-5w8x</guid>
    </item>
  </channel>
</rss>
