Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CLSA-2026-1790719586
  • TuxCare:npm/joi
TuxCare security update for joi (1 CVE) 7 hours ago
  • Fix available
GHSA-6h2x-m376-mqjq
  • npm/joi
joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()` 11 hours ago
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-92599
  • github.com/hapijs/joi
Joi before 17.13.7 and 18.2.6 ReDoS via isoDate 16 Sep
  • Fix available
  • Severity - 8.7 (High)
CVE-2026-90771
  • github.com/hapijs/joi
joi before 17.13.8 and 18.2.9 Prototype Pollution via messages 13 Sep
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-6w3j-5fw6-r9vr
  • npm/@hapi/joi
  • npm/joi
joi: Prototype pollution via a `__proto__` language key in custom messages 08 Sep
  • Fix available
  • Severity - 3.7 (Low)
GHSA-gg4h-3hg2-grpc
  • npm/joi
joi: object().rename() with a template target can set the validated object's prototype 08 Sep
  • Fix available
  • Severity - 3.7 (Low)
CVE-2026-84368
  • github.com/hapijs/joi
joi: Prototype pollution via a `__proto__` language key in custom messages 01 Sep
  • Fix available
  • Severity - 3.7 (Low)
CVE-2026-84367
  • github.com/hapijs/joi
joi: object().rename() with a template target can set the validated object's prototype 01 Sep
  • Fix available
  • Severity - 3.7 (Low)
CVE-2026-48038
  • github.com/hapijs/joi
joi: Uncaught RangeError on deeply nested input through recursive `link()` schemas 14 Jul
  • Fix available
  • Severity - 5.3 (Medium)
ROOT-APP-NPM-CVE-2026-48038
  • Root:npm/@rootio/joi
  • Root:npm/joi
CVE-2026-48038 in @rootio/joi - Patched by Root 10 Jul
  • Fix available
GHSA-q7cg-457f-vx79
  • npm/joi
joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas 11 Jun
  • Fix available
  • Severity - 5.3 (Medium)
MAL-2026-3765
  • npm/joi-pack
Malicious code in joi-pack (npm) 14 May
  • No fix available
MAL-2025-175719
  • npm/kupaio-kula-joi
Malicious code in kupaio-kula-joi (npm) 12 Nov 2025
  • No fix available