VDB
Sign up
MEDIUM

GHSA-2g4f-4pwh-qvx6

ajv has ReDoS when using `$data` option

Quick fix

GHSA-2g4f-4pwh-qvx6 — ajv: upgrade to the fixed version with the command below.

npm install ajv@8.18.0

Details

ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to Regular Expression Denial of Service (ReDoS) when the `$data` option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax (`$data` reference), which is passed directly to the JavaScript `RegExp()` constructor without validation. An attacker can inject a malicious regex pattern (e.g., `\"^(a|a)*$\"`) combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with `$data`: true for dynamic schema validation.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ajv
Introduced in: 7.0.0-alpha.0Fixed in: 8.18.0
Fixnpm install ajv@8.18.0
npm/ajv
Introduced in: 0Fixed in: 6.14.0
Fixnpm install ajv@6.14.0

References