| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8hq9-phh3-p2wp | Elysia Cookie Value Prototype Pollution |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 18 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elysiajs
Elysiajs elysia |
|
| Vendors & Products |
Elysiajs
Elysiajs elysia |
Wed, 18 Mar 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server communication. Prior to version 1.4.27, an Elysia cookie can be overridden by prototype pollution , eg. `__proto__`. This issue is patched in 1.4.27. As a workaround, use t.Cookie validation to enforce validation value and/or prevent iterable over cookie if possible. | |
| Title | Elysia Cookie Value Prototype Pollution | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-18T18:39:09.024Z
Reserved: 2026-03-09T19:02:25.013Z
Link: CVE-2026-31865
Updated: 2026-03-18T18:39:05.576Z
Status : Awaiting Analysis
Published: 2026-03-18T04:17:19.393
Modified: 2026-03-18T14:52:44.227
Link: CVE-2026-31865
No data.
OpenCVE Enrichment
Updated: 2026-03-18T10:41:59Z
Github GHSA