Vulnerabilities/

joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas

Severity:
Medium

Description

Denial of service via untrapped exception in services validating user-supplied JSON / object input with recursive link schemas.

The blast radius depends on how the application invokes joi:

Recommendation

Update the joi package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
joi
Anything's wrong? Let us know Last updated on June 12, 2026