DEBIAN-CVE-2025-69873

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 11 Feb 2026, 19:15
Last modified:15 Jun 2026, 19:06

Vulnerability Summary

Overall Risk (default)
low
12/100
CVSS Score
2.9 LOW
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 Feb 2026, 19:15
Published
Vulnerability first disclosed
15 Jun 2026, 19:06
Last Modified
Vulnerability information updated

Description

ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., "^(a|a)*$") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation. This issue is also fixed in version 6.14.0.

CVSS Metrics

  • v3.1LOWScore: 2.9CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Systems

  • debiannode-ajv

    all | all | all | all | < 8.18.0~ds+~cs6.1.1-1

References (1)