CVE-2026-90771

Source
https://cve.org/CVERecord?id=CVE-2026-90771
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90771.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90771
Published
2026-09-13T10:45:42Z
Modified
2026-09-15T03:48:23Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
joi before 17.13.8 and 18.2.9 Prototype Pollution via messages
Details

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts proto as an error code. Attackers can supply proto keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-1321"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90771.json"
}
References

Affected packages

Git / github.com/hapijs/joi

Affected ranges

Type
GIT
Repo
https://github.com/hapijs/joi
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "16.0.0"
        },
        {
            "fixed": "17.13.8"
        },
        {
            "introduced": "18.0.0"
        },
        {
            "fixed": "18.2.9"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v16.*
v16.0.0
v16.0.1
v16.1.0
v16.1.1
v16.1.2
v16.1.3
v16.1.4
v16.1.5
v16.1.6
v16.1.7
v16.1.8
v17.*
v17.0.0
v17.0.1
v17.0.2
v17.1.0
v17.1.1
v17.10.0
v17.10.1
v17.10.2
v17.11.0
v17.11.1
v17.12.0
v17.12.1
v17.12.2
v17.12.3
v17.13.0
v17.13.1
v17.13.2
v17.13.3
v17.13.4
v17.13.5
v17.13.6
v17.13.7
v17.2.0
v17.2.1
v17.3.0
v17.4.0
v17.4.1
v17.4.2
v17.4.3
v17.5.0
v17.6.0
v17.6.1
v17.6.2
v17.6.3
v17.6.4
v17.7.0
v17.7.1
v17.8.0
v17.8.1
v17.8.2
v17.8.3
v17.8.4
v17.9.0
v17.9.1
v17.9.2
v18.*
v18.0.0
v18.0.1
v18.0.2
v18.1.0
v18.1.1
v18.1.2
v18.2.0
v18.2.1
v18.2.2
v18.2.3
v18.2.4
v18.2.5
v18.2.6
v18.2.7
v18.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90771.json"