### Impact Denial of service via untrapped exception in services validating user-supplied JSON / object input with recursive link schemas. The blast radius depends on how the application invokes joi: - Highest impact: `validate()` called without `try/catch` in a request handler would cause an unhandled exception, potentially crashing the process. - Lower impact: `validateAsync()` or `validate()` inside a `try/catch`, the validation fails, but the error type is `RangeError` rather than a structured `ValidationError`, complicating error handling. ### Patches Upgrade to version >= 18.2.1. ### Workarounds Try/catch the validation to avoid uncaught exceptions. ### References - Pull request: hapijs/joi#3113
Update joi to 18.2.1; joi to 18.2.1; joi to 17.13.4 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanjoi has an uncaught RangeError on deeply nested input through recursive `link()` schemas affects joi (npm), joi (npm), joi (npm). Severity is medium. ### Impact Denial of service via untrapped exception in services validating user-supplied JSON / object input with recursive link schemas. The blast radius depends on how the application invokes joi: - Highest impact: `validate()` called without `try/catch` in a request handler would cause an unhandled exception, potentially crashing the process. - Lower impact: `validateAsync()` or `validate()` inside a `try/catch`, the validation fails, but the error type is `RangeError` rather than a structured `ValidationError`, complicating error handling. ### Patches Upgrade to version >= 18.2.1. ### Workarounds Try/catch the validation to avoid uncaught exceptions. ### References - Pull request: hapijs/joi#3113
AI coding agents often install or upgrade packages automatically in npm. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
### Impact Denial of service via untrapped exception in services validating user-supplied JSON / object input with recursive link schemas. The blast radius depends on how the application invokes joi: - Highest impact: `validate()` called without `try/catch` in a request handler would cause an unhandled exception, potentially crashing the process. - Lower impact: `validateAsync()` or `validate()` inside a `try/catch`, the validation fails, but the error type is `RangeError` rather than a structured `ValidationError`, complicating error handling. ### Patches Upgrade to version >= 18.2.1. ### Workarounds Try/catch the validation to avoid uncaught exceptions. ### References - Pull request: hapijs/joi#3113
Update joi to 18.2.1; joi to 18.2.1; joi to 17.13.4 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanjoi has an uncaught RangeError on deeply nested input through recursive `link()` schemas affects joi (npm), joi (npm), joi (npm). Severity is medium. ### Impact Denial of service via untrapped exception in services validating user-supplied JSON / object input with recursive link schemas. The blast radius depends on how the application invokes joi: - Highest impact: `validate()` called without `try/catch` in a request handler would cause an unhandled exception, potentially crashing the process. - Lower impact: `validateAsync()` or `validate()` inside a `try/catch`, the validation fails, but the error type is `RangeError` rather than a structured `ValidationError`, complicating error handling. ### Patches Upgrade to version >= 18.2.1. ### Workarounds Try/catch the validation to avoid uncaught exceptions. ### References - Pull request: hapijs/joi#3113
AI coding agents often install or upgrade packages automatically in npm. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| joinpm | <18.2.1 | 18.2.1 |
|---|
| joinpm | >=18.0.0,<18.2.1 | 18.2.1 |
|---|
| joinpm | <17.13.4 | 17.13.4 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| joinpm | <18.2.1 | 18.2.1 |
|---|
| joinpm | >=18.0.0,<18.2.1 | 18.2.1 |
|---|
| joinpm | <17.13.4 | 17.13.4 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard