Regular Expression Denial of Service in is-my-json-valid
High severity
GitHub Reviewed
Published
Oct 24, 2017
to the GitHub Advisory Database
•
Updated Oct 17, 2025
Description
Published by the National Vulnerability Database
Feb 23, 2016
Published to the GitHub Advisory Database
Oct 24, 2017
Reviewed
Jun 16, 2020
Last updated
Oct 17, 2025
Version of
is-my-json-valid
before 2.12.4 are vulnerable to regular expression denial of service (ReDoS) via the email validation function.Recommendation
Update to version 2.12.4 or later.
References