PT-2026-94116 · Npm · Joi
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
joi versions 17.2.0 through 17.13.6
joi versions 18.0.0 through 18.2.5
Description
A regular expression denial of service exists in the
Joi.string().isoDate() validation rule. An unanchored regular expression causes the engine to restart its search from every position in the string when a valid ISO date is followed by a long sequence of fractional-second digits. This results in processing time proportional to the square of the input length, allowing a remote attacker to stall the application with a single request.Recommendations
Update joi versions 17.2.0 through 17.13.6 to version 17.13.7.
Update joi versions 18.0.0 through 18.2.5 to version 18.2.6.
As a temporary workaround, cap the length of the string before it reaches joi.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joi