nodejs-is-my-json-valid: ReDoS when validating JSON fields with email format
Published Mar 30, 2021
5.3
MEDIUMCVSS 3.1
EPSS 1.20%
Description
It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON fields defined to have email format. A specially crafted JSON file could cause it to consume an excessive amount of CPU time when validated.
Affected products
- Vendor n/a Product Nodejs-IS-MY-Json-Valid Defaultn/a
- Version is-myjson-valid 2.17.2, is-myjson-valid 1.4.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Nodejs-IS-MY-Json-Valid | n/a |
|
- < 1.4.1
- ≥ 2.0.0 · < 2.17.2
No data.
Red Hat Quay 3
quay/quay-rhel8:v3.6.0-62
Fixed · RHSA-2021:3917
Red Hat Enterprise Linux 8
nodejs-is-my-json-valid
Not affected
Red Hat Mobile Application Platform 4
nodejs-is-my-json-valid
Affected
Red Hat OpenShift Enterprise 3
nodejs-is-my-json-valid
Not affected
Red Hat Software Collections
rh-nodejs6-nodejs-is-my-json-valid
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Quay 3 | quay/quay-rhel8:v3.6.0-62 | Fixed | RHSA-2021:3917 |
| Red Hat Enterprise Linux 8 | nodejs-is-my-json-valid | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | nodejs-is-my-json-valid | Affected | n/a |
| Red Hat OpenShift Enterprise 3 | nodejs-is-my-json-valid | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs6-nodejs-is-my-json-valid | Will not fix | n/a |
is-my-json-valid
npm
Introduced 0 Fixed 1.4.1is-my-json-valid
npm
Introduced 2.0.0 Fixed 2.17.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | is-my-json-valid | 0 | 1.4.1 |
| npm | is-my-json-valid | 2.0.0 | 2.17.2 |
Remediation
Red Hat statement
In Red Hat Quay the is-my-json-valid library is included as a build time dependency of protractor. It's only used at build time, not at runtime reducing the impact to low.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.20% (0.01204) | 67.15th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.20% (0.01204) | 66.88th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.12% (0.00117) | 46.01th | v3 (v2023.03.01) |
| Dec 13, 2023 | 0.12% (0.00117) | 45.31th | v3 (v2023.03.01) |
| Nov 3, 2023 | 0.10% (0.00102) | 41.65th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.09% (0.00088) | 36.05th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.62% (0.00624) | 17.80th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.62% (0.00624) | 0.00th | v1 |
References (8)
- https://access.redhat.com/security/cve/CVE-2018-1107 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1546357 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://github.com/advisories/GHSA-4hpf-3wq7-5rpr Advisory
- https://github.com/mafintosh/is-my-json-valid/commit/b3051b277f7caa08cd2edc6f74f50aeda65d2976
- https://github.com/mafintosh/is-my-json-valid/pull/159
- https://nvd.nist.gov/vuln/detail/CVE-2018-1107
- https://snyk.io/vuln/npm:is-my-json-valid:20180214 x_refsource_MISCExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-1107
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-1107 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1546357 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://github.com/advisories/GHSA-4hpf-3wq7-5rpr | Advisory | |
| https://github.com/mafintosh/is-my-json-valid/commit/b3051b277f7caa08cd2edc6f74f50aeda65d2976 | ||
| https://github.com/mafintosh/is-my-json-valid/pull/159 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2018-1107 | ||
| https://snyk.io/vuln/npm:is-my-json-valid:20180214 | x_refsource_MISCExploitThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-1107 |
Change history (0)
No recorded changes yet.