joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service is possible via an untrapped exception in services validating user-supplied JSON or object input with recursive link() schemas. When validate() is called without try/catch in a request handler, deeply nested input can trigger an unhandled RangeError and potentially crash the process; lower-impact paths using validateAsync() or try/catch produce a RangeError instead of a structured ValidationError. This issue is fixed in versions 17.13.4 and 18.2.1.
References
Configurations
No configuration.
History
14 Jul 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 20:17
Updated : 2026-07-15 20:22
NVD link : CVE-2026-48038
Mitre link : CVE-2026-48038
CVE.ORG link : CVE-2026-48038
JSON object : View
Products Affected
No product.
CWE
CWE-248
Uncaught Exception
