joi has 3 CVEs on record. 2 were published in the last 90 days. The median CVSS is 3.7 (low).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 3.7
- Publish → KEV
- —
- Last 90 days
- 2 prev 1
Weakness classes
Products
- joi 3
Worst active — by depth score
CVE-2026-48038Medium· 5.3joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas29CVE-2026-84368Low· 3.7joi is a schema description language and data validator for JavaScript20CVE-2026-84367Low· 3.7joi is a schema description language and data validator for JavaScript20
joi vulnerabilities
CVEs affecting joi, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-84367Low· 3.7joi is a schema description language and data validator for JavaScript
joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementation used by object().rename() permits a schema that renames keys with a r…
CVE-2026-84368Low· 3.7joi is a schema description language and data validator for JavaScript
joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and the successor joi package contain prototype pollution in lib/messages.js, where export…
CVE-2026-48038Medium· 5.3joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas
joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas