joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas
RSS Feed
MODERATE
GHSA-q7cg-457f-vx79
CVE-2026-48038
Description:
Impact
Denial of service via untrapped exception in services validating user-supplied JSON / object input with recursive link schemas.
The blast radius depends on how the application invokes joi:
- Highest impact:
validate()called withouttry/catchin a request handler would cause an unhandled exception, potentially crashing the process. - Lower impact:
validateAsync()orvalidate()inside atry/catch, the validation fails, but the error type isRangeErrorrather than a structuredValidationError, complicating error handling.
Patches
Upgrade to version >= 18.2.1.
Workarounds
Try/catch the validation to avoid uncaught exceptions.
References
- Pull request: hapijs/joi#3113
Affected Packages
| Ecosystem | Package | Vulnerable Versions | Patched Version |
|---|---|---|---|
| npm |
joi
|
< 17.13.4>= 18.0.0, < 18.2.1 |
17.13.4
|
Actions
Advisory Details
| Published: | June 11, 2026 4 months ago |
| Updated: | October 07, 2026 2 days ago |
| CVSS Score: | 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| EPSS: | 0.52% 43th percentile |
| Source: | Github |
| Classification: | GENERAL |
| UUID: | GSA_kwCzR0hTQS1xN2NnLTQ1N2Ytdng3Oc4ABYjf |