highCVSS 7.5Vulnerability

CVE-2026-92599

### Impact Any application that validates a user-supplied string with `Joi.string().isoDate()` can be stalled by a single request. One of the regular expressions the rule runs over the input was unanchored, so a valid ISO date followed by a long run of fractional-second digits made the regex engine restart its search from every position in the string, costing time proportional to the square of the input length. 64 KB of digits costs about 1.4 s and 256 KB about 22 s. ### Patches Upgrade to version 17.13.7 or 18.2.6 depending on your current major version. ### Workarounds None except capping the length of the string before it reaches joi.

Properties

summary
joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`
severity
high
epss_score
0.00582
cvss_score
7.5
retrieved_at
2026-10-06T03:06:48+00:00
ghsa_published
2026-09-29T18:07:42Z
source_url
https://github.com/advisories/GHSA-6h2x-m376-mqjq
ghsa_updated
2026-10-05T23:31:12Z
ghsa_id
GHSA-6h2x-m376-mqjq
last_source
FIRST EPSS
cve_id
CVE-2026-92599
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-10-06T02:58:32+00:00
is_ghsa_only
false
epss_percentile
0.45884

Related Entities (5)

ENRICHED_BY (1)

→[Source]FIRST EPSS

HAS_WEAKNESS (1)

→[Weakness]Inefficient Regular Expression Complexity

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/joi

AFFECTS (1)

→[Software]npm/joi

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92599 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal