highCVSS 7.5Vulnerability

GHSA-6h2x-m376-mqjq

### Impact Any application that validates a user-supplied string with `Joi.string().isoDate()` can be stalled by a single request. One of the regular expressions the rule runs over the input was unanchored, so a valid ISO date followed by a long run of fractional-second digits made the regex engine restart its search from every position in the string, costing time proportional to the square of the input length. 64 KB of digits costs about 1.4 s and 256 KB about 22 s. ### Patches Upgrade to version 17.13.7 or 18.2.6 depending on your current major version. ### Workarounds None except capping the length of the string before it reaches joi.

Properties

severity
high
summary
joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`
cvss_score
7.5
retrieved_at
2026-09-29T18:18:48+00:00
ghsa_published
2026-09-29T18:07:42Z
source_url
https://github.com/advisories/GHSA-6h2x-m376-mqjq
ghsa_updated
2026-09-29T18:07:43Z
ghsa_id
GHSA-6h2x-m376-mqjq
last_source
GitHub Advisory Database
cve_id
GHSA-6h2x-m376-mqjq
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-29T18:18:48+00:00
is_ghsa_only
true

Related Entities (4)

VULNERABLE_TO (1)

←[Software]npm/joi

AFFECTS (1)

→[Software]npm/joi

HAS_WEAKNESS (1)

→[Weakness]Inefficient Regular Expression Complexity

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-6h2x-m376-mqjq (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal