Executive brief
is-my-json-valid is a JavaScript library used to validate JSON data against schemas. A regular expression in the library is susceptible to catastrophic backtracking, which could allow an attacker to cause a denial of service by providing specially crafted input that forces excessive CPU consumption during validation.
Technical details
The vulnerability is a regular expression denial of service (ReDoS) in the is-my-json-valid JSON schema validation library, caused by problematic regex patterns that exhibit catastrophic backtracking behavior. The vulnerable regexes are used during JSON schema validation, which typically runs automatically when processing untrusted input without additional authentication or network access restrictions. An attacker can craft malicious JSON input containing strings that trigger exponential backtracking in the validation regex, causing high CPU consumption and denial of service. The issue was addressed in versions 1.4.1 and 2.17.2 through improved regex patterns that avoid catastrophic backtracking, as demonstrated in PR #159 which explicitly addresses this issue.
Affected products
- mafintosh is-my-json-valid 0 to 1.4.0 and 2.0.0 to 2.17.1
Timeline
- 2020-08-19: disclosed
- 2018-02-14: patched: Fix merged in PR #159 with commit b3051b2