CVE-2018-1107: Is-My-JSON-Valid Project Is-My-JSON-Valid
Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.
It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON fields defined to have email format. A specially crafted JSON file could cause it to consume an excessive amount of CPU time when validated.
Affected products
- Is-My-JSON-Valid Project Is-My-JSON-Valid: before 1.4.1 (fixed in 1.4.1); from 2.0.0, before 2.17.2 (fixed in 2.17.2)
Published 2021-03-30. Last modified 2026-06-17.