Vulnerability library
Security checkJune 12, 2026

joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmjoi

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Denial of service via untrapped exception in services validating user-supplied JSON / object input with recursive link schemas.

The blast radius depends on how the application invokes joi:

  • Highest impact: validate() called without try/catch in a request handler would cause an unhandled exception, potentially crashing the process.

Recommendation

Update the joi package to the latest compatible version. Followings are version details:

  • Affected version(s): **< 17.13.4 >= 18.0.0, < 18.2.1**
  • Patched version(s): **17.13.4 18.2.1**

References

Could your website be exposed too?

SmartScanner can check your website for joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated June 12, 2026