PT-2026-94116 · Npm · Joi

·

CVE-2026-92599

·

Published

2026-09-16

·

Updated

2026-09-29

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions joi versions 17.2.0 through 17.13.6 joi versions 18.0.0 through 18.2.5
Description A regular expression denial of service exists in the Joi.string().isoDate() validation rule. An unanchored regular expression causes the engine to restart its search from every position in the string when a valid ISO date is followed by a long sequence of fractional-second digits. This results in processing time proportional to the square of the input length, allowing a remote attacker to stall the application with a single request.
Recommendations Update joi versions 17.2.0 through 17.13.6 to version 17.13.7. Update joi versions 18.0.0 through 18.2.5 to version 18.2.6. As a temporary workaround, cap the length of the string before it reaches joi.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92599
GHSA-6H2X-M376-MQJQ

Affected Products

Joi