Bug 2538354 (CVE-2026-92599)

Summary: CVE-2026-92599 joi: joi: Denial of Service via `isoDate` validation regular expression
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akhatavk, aos-team-art-private, asdas, cdrage, dfreiber, dpaolell, drow, dymurray, gparvin, ibolton, jbalunas, jburrell, jdelft, jmatthew, jmontleo, jupierce, lchilton, lgarciaa, mbiarnes, pgaikwad, pjindal, ppalepu, ppostler, prdhamdh, rhaigner, rhel-process-autobot, rjohnson, rushinde, sdawley, sfeifer, sghai, sidsharm, slucidi, sseago, suppawar, tsze, vkumar, vlaad, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in joi. A remote attacker can exploit an unanchored regular expression in the `Joi.string().isoDate()` validation rule by supplying a specially crafted string. This input, consisting of a valid ISO date followed by a long sequence of fractional-second digits, causes the regular expression engine to consume excessive processing time. This vulnerability leads to a Regular Expression Denial of Service (ReDoS), allowing the attacker to stall the application with a single request.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-22 18:14:58 UTC
joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to the input is unanchored, so a valid ISO date followed by a long run of fractional-second digits causes the regex engine to restart its search from every position in the string, yielding time proportional to the square of the input length (about 1.4 s for 64 KB of digits and about 22 s for 256 KB). A remote attacker who can supply a string to an isoDate validation can stall the application with a single request. Fixed in 17.13.7 and 18.2.6; as a workaround, cap the length of the string before it reaches joi.