CVE-2018-1107: Is-My-JSON-Valid Project Is-My-JSON-Valid

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON fields defined to have email format. A specially crafted JSON file could cause it to consume an excessive amount of CPU time when validated.

Affected products

Published 2021-03-30. Last modified 2026-06-17.