CVE-2026-92599
Joi isoDate validation denial of service (17.x version advisory)
- Severity
- high
- Affected product
- joi
- Affected versions
- joi ≥ 17.2.0, < 17.13.7
- Affected versions
- joi ≥ 18.0.0, < 18.2.6
- Fixed in
- joi 17.13.7
- Fixed in
- joi 18.2.6
- Added to NewScan
- 2026-09-18
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints joi from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-18. Version source: exact joi pins in package.json, package-lock.json or yarn.lock through mine_versions' existing parser and pack-derived aliases. Version-match only; use of isoDate on untrusted input is not confirmed. Source: https://github.com/hapijs/joi/security/advisories/GHSA-6h2x-m376-mqjq. Its 17.x range is >=17.2.0 <17.13.7; the separate 18.x row preserves the patched 17.x gap. CVE association is from the saved NVD triage; the maintainer page has no CVE assigned. No resource-exhaustion or timing probe is sent.
COMPONENT VERSION RANGE
NewScan fingerprints joi from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-18. The 18.x arm of https://github.com/hapijs/joi/security/advisories/GHSA-6h2x-m376-mqjq: >=18.0.0 <18.2.6. Exact npm manifest/lockfile pins supply the version through mine_versions. CVE association is from the saved NVD triage. Version-match only; this does not establish that an application exposes isoDate validation to untrusted input. No timing or resource-exhaustion probe is sent.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →