joi
npm5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting joipage 1 of 1
- CVE-2026-48038MEDIUMCVSS 5.3EG 5.3fixed in 18.2.1 or 17.13.4, by version range2026-06-11
joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service is possible via an untrapped exception in services validating user-supplied JSON or object input with recursive link() s…
- CVE-2026-84367LOWCVSS 3.7EG 3.7fixed in 17.13.5 or 18.2.4, by version range2026-09-01
joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementation used by object().rename() permits a schema that renames keys with a reg…
- CVE-2026-84368LOWCVSS 3.7EG 3.7fixed in 17.13.6 or 18.2.5, by version range2026-09-01
joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and the successor joi package contain prototype pollution in lib/messages.js, where exports.…
- CVE-2026-90771LOWCVSS 3.7EG 3.7fixed in 17.13.8 or 18.2.9, by version range2026-09-13
joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returne…
- CVE-2026-92599HIGHCVSS 7.5EG 7.5fixed in 17.13.7 or 18.2.6, by version range2026-09-16
joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to the…
Check whether joi is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for joi CVEs against the assets you own.
Book a Demo →