Impact
Joi, the npm package used in hapi.js, contains a regular-expression-based denial‑of‑service flaw in its isoDate validation rule. The rule applies an unanchored regex that, when faced with a valid ISO date followed by a long series of fractional‑second digits, causes the engine to restart the search at every position. This leads to quadratic‑time processing that can stall the application for seconds to minutes on a single request. The flaw would allow an attacker controlling the input string to a Joi.string().isoDate() call to exhaust I/O, CPU, or memory resources and deny service to legitimate users.
Affected Systems
Versions of Joi from 17.2.0 up to, but not including, 17.13.7 and from 18.0.0 up to, but not including, 18.2.6 are affected. These releases are used by projects built on the hapi.js framework. Administrators should identify any dependency references to these vulnerable ranges and plan upgrades accordingly.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score falls below 1%, suggesting that existing exploitation attempts are rare, but the flaw is not listed in the CISA KEV catalog. Nonetheless, because the vulnerability can be triggered by any supplied string to the isoDate validator, a remote attacker with the ability to send arbitrary input could cause noticeable degradation. The attack path is straightforward: supply a crafted string exceeding typical fractional‑second lengths; the regex engine will process it disproportionately, resulting in a denial of service.
OpenCVE Enrichment
Github GHSA