An open index of dependabot pull requests across open source projects.

joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas

RSS Feed MODERATE
GHSA-q7cg-457f-vx79 CVE-2026-48038
Description:

Impact

Denial of service via untrapped exception in services validating user-supplied JSON / object input with recursive link schemas.

The blast radius depends on how the application invokes joi:

  • Highest impact: validate() called without try/catch in a request handler would cause an unhandled exception, potentially crashing the process.
  • Lower impact: validateAsync() or validate() inside a try/catch, the validation fails, but the error type is RangeError rather than a structured ValidationError, complicating error handling.

Patches

Upgrade to version >= 18.2.1.

Workarounds

Try/catch the validation to avoid uncaught exceptions.

References

  • Pull request: hapijs/joi#3113
Affected Packages
Ecosystem Package Vulnerable Versions Patched Version
npm joi < 17.13.4
>= 18.0.0, < 18.2.1
17.13.4
Related Dependabot Pull Requests
Advisory Details
Published: June 11, 2026 4 months ago
Updated: October 07, 2026 2 days ago
CVSS Score: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS: 0.52% 43th percentile
Source: Github
Classification: GENERAL
UUID: GSA_kwCzR0hTQS1xN2NnLTQ1N2Ytdng3Oc4ABYjf