Description
joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to the input is unanchored, so a valid ISO date followed by a long run of fractional-second digits causes the regex engine to restart its search from every position in the string, yielding time proportional to the square of the input length (about 1.4 s for 64 KB of digits and about 22 s for 256 KB). A remote attacker who can supply a string to an isoDate validation can stall the application with a single request. Fixed in 17.13.7 and 18.2.6; as a workaround, cap the length of the string before it reaches joi.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Regular Expression
Action: Immediate Patch
AI Analysis

Impact

Joi, the npm package used in hapi.js, contains a regular-expression-based denial‑of‑service flaw in its isoDate validation rule. The rule applies an unanchored regex that, when faced with a valid ISO date followed by a long series of fractional‑second digits, causes the engine to restart the search at every position. This leads to quadratic‑time processing that can stall the application for seconds to minutes on a single request. The flaw would allow an attacker controlling the input string to a Joi.string().isoDate() call to exhaust I/O, CPU, or memory resources and deny service to legitimate users.

Affected Systems

Versions of Joi from 17.2.0 up to, but not including, 17.13.7 and from 18.0.0 up to, but not including, 18.2.6 are affected. These releases are used by projects built on the hapi.js framework. Administrators should identify any dependency references to these vulnerable ranges and plan upgrades accordingly.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score falls below 1%, suggesting that existing exploitation attempts are rare, but the flaw is not listed in the CISA KEV catalog. Nonetheless, because the vulnerability can be triggered by any supplied string to the isoDate validator, a remote attacker with the ability to send arbitrary input could cause noticeable degradation. The attack path is straightforward: supply a crafted string exceeding typical fractional‑second lengths; the regex engine will process it disproportionately, resulting in a denial of service.

Generated by OpenCVE AI on September 18, 2026 at 05:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Joi to version 17.13.7 or newer in the 18.x line (18.2.6 or later).
  • If upgrading is not immediately possible, limit the maximum length of strings sent to Joi.string().isoDate() to a reasonable value before validation.
  • Consider implementing request size limits or API gateway rate limiting to prevent excessive payloads from reaching the application.

Generated by OpenCVE AI on September 18, 2026 at 05:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6h2x-m376-mqjq joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`
History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat hummingbird
CPEs cpe:/a:redhat:hummingbird:1
Vendors & Products Redhat
Redhat hummingbird
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Hapijs
Hapijs joi
Vendors & Products Hapijs
Hapijs joi

Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to the input is unanchored, so a valid ISO date followed by a long run of fractional-second digits causes the regex engine to restart its search from every position in the string, yielding time proportional to the square of the input length (about 1.4 s for 64 KB of digits and about 22 s for 256 KB). A remote attacker who can supply a string to an isoDate validation can stall the application with a single request. Fixed in 17.13.7 and 18.2.6; as a workaround, cap the length of the string before it reaches joi.
Title Joi before 17.13.7 and 18.2.6 ReDoS via isoDate
Weaknesses CWE-1333
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T20:06:43.275Z

Reserved: 2026-09-16T13:48:49.970Z

Link: CVE-2026-92599

cve-icon Vulnrichment

Updated: 2026-09-18T20:06:38.577Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T22:18:30.980

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92599

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T21:47:03Z

Links: CVE-2026-92599 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:15:03Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity