Skip to main content

Vendor/product archive

elysiajs / elysia CVEs

Beta · best-effort

4 CVEs tagged to elysiajs / elysia1 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-31865

Published Mar 18, 2026

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server communication. Prior to version 1.4.27, an Elysia cookie can be o…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-30837

Published Mar 10, 2026

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Prior to 1.4.26 , t.String({ format: 'url' }) is vu…

CVSS 7.5 · High
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-66457

Published Dec 9, 2025

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.17 and below are subject to arbitrary…

CVSS 7.5 · High
evidence mentions
6
Buzz score
29.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-66456

Published Dec 9, 2025

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 through 1.4.16 contain a prototype p…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1