Executive brief
is-my-json-valid is a Node.js library for validating JSON data against schemas. The library contains a flawed regular expression in the utc-millisec validator that can be exploited with a specially crafted string to cause the application to hang, blocking the event loop and making the service unresponsive.
Technical details
The vulnerability is a regular expression denial of service (ReDoS) flaw in the utc-millisec format validator of is-my-json-valid versions prior to 2.12.4. The vulnerable regular expression exhibits excessive backtracking when processing certain malformed input strings, causing the event loop to block indefinitely. An attacker can trigger this by providing a crafted JSON string to an application that validates input using this library, resulting in a denial of service condition. The fix is available in version 2.12.4 and later.
Affected products
- npm is-my-json-valid <2.12.4
Timeline
- 2018-07-31: disclosed
- 2012.4: patched: Fix available in version 2.12.4
- 2020-06-16: other: Advisory withdrawn as accidental duplicate