icon

We found results for “

CVE-2025-12758

Good to know:

icon
icon
icon

Date: November 27, 2025

Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (️, ︎) appearing in a sequence which lead to improper string length calculation. This can lead to an application using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer overflows in other system components, or denial-of-service.

Severity Score

Severity Score

Weakness Type (CWE)

Encoding Error

CWE-172

Incomplete Filtering of One or More Instances of Special Elements

CWE-792

Top Fix

icon

Upgrade Version

Upgrade to version validator - 13.15.22;validator - 13.15.22;validator - 13.15.22;https://github.com/validatorjs/validator.js.git - 13.15.22

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us