← All CVEs NewScan detects
high

CVE-2026-92599

Joi isoDate validation denial of service (17.x version advisory)

Severity
high
Affected product
joi
Affected versions
joi ≥ 17.2.0, < 17.13.7
Affected versions
joi ≥ 18.0.0, < 18.2.6
Fixed in
joi 17.13.7
Fixed in
joi 18.2.6
Added to NewScan
2026-09-18
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints joi from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-18. Version source: exact joi pins in package.json, package-lock.json or yarn.lock through mine_versions' existing parser and pack-derived aliases. Version-match only; use of isoDate on untrusted input is not confirmed. Source: https://github.com/hapijs/joi/security/advisories/GHSA-6h2x-m376-mqjq. Its 17.x range is >=17.2.0 <17.13.7; the separate 18.x row preserves the patched 17.x gap. CVE association is from the saved NVD triage; the maintainer page has no CVE assigned. No resource-exhaustion or timing probe is sent.

COMPONENT VERSION RANGE

NewScan fingerprints joi from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-18. The 18.x arm of https://github.com/hapijs/joi/security/advisories/GHSA-6h2x-m376-mqjq: >=18.0.0 <18.2.6. Exact npm manifest/lockfile pins supply the version through mine_versions. CVE association is from the saved NVD triage. Version-match only; this does not establish that an application exposes isoDate validation to untrusted input. No timing or resource-exhaustion probe is sent.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →