VYPR

Joi

by hapijs

Source repositories

CVEs (3)

  • CVE-2026-48038MedJul 14, 2026
    risk 0.27cvss 5.3epss 0.01

    joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service is possible via an untrapped exception in services validating user-supplied JSON or object input with recursive link() schemas. When validate() is called…

  • CVE-2026-84368LowSep 1, 2026
    risk 0.17cvss 3.7epss 0.00

    joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and the successor joi package contain prototype pollution in lib/messages.js, where exports.compile() and exports.merge() reuse…

  • CVE-2026-84367LowSep 1, 2026
    risk 0.17cvss 3.7epss 0.00

    joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementation used by object().rename() permits a schema that renames keys with a regular-expression source and a…