-
-
Notifications
You must be signed in to change notification settings - Fork 132
Open
Description
While working on zenstack project, I identified a security vulnerability in the Elysia framework dependency related to URL format validation. The issue corresponds to CVE-2026-30837, which allows attackers to trigger a Regular Expression Denial of Service (ReDoS) due to inefficient regex handling in URL validation. The vulnerability occurs when specially crafted URL inputs are processed by the regex used
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels