Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Qrn12580

#32834of 57,416
8.7Total CVSS
Vulnerabilities · 1
PT-2026-94116
8.7
2026-09-16
Npm · Joi · CVE-2026-92599
**Name of the Vulnerable Software and Affected Versions** joi versions 17.2.0 through 17.13.6 joi versions 18.0.0 through 18.2.5 **Description** A regular expression denial of service exists in the `Joi.string().isoDate()` validation rule. An unanchored regular expression causes the engine to restart its search from every position in the string when a valid ISO date is followed by a long sequence of fractional-second digits. This results in processing time proportional to the square of the input length, allowing a remote attacker to stall the application with a single request. **Recommendations** Update joi versions 17.2.0 through 17.13.6 to version 17.13.7. Update joi versions 18.0.0 through 18.2.5 to version 18.2.6. As a temporary workaround, cap the length of the string before it reaches joi.