CVE-2025-12758: Incomplete Filtering of One or More Instances of Special Elements in validator
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This can lead to an application using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer overflows in other system components, or denial-of-service.
AI Analysis
Technical Summary
CVE-2025-12758 affects the validator package prior to version 13.15.22. The vulnerability arises from incomplete filtering of special Unicode variation selectors (\uFE0F, \uFE0E) in the isLength() function. This flaw causes the function to miscalculate string lengths, allowing applications relying on isLength for input validation to accept strings significantly longer than expected. The improper length validation can result in downstream impacts such as database data truncation, buffer overflows in other system components, or denial-of-service scenarios.
Potential Impact
Applications using the vulnerable versions of validator for input length validation may accept longer strings than intended, leading to potential data truncation in databases, buffer overflow vulnerabilities in other components, or denial-of-service conditions. This can compromise application stability and data integrity.
Mitigation Recommendations
A fix is available in validator version 13.15.22. Users should upgrade to version 13.15.22 or later to address this vulnerability. Patch status is confirmed by the versioning information indicating versions before 13.15.22 are affected.
CVE-2025-12758: Incomplete Filtering of One or More Instances of Special Elements in validator
Description
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This can lead to an application using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer overflows in other system components, or denial-of-service.
CVSS v4.0
Score 8.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-12758 affects the validator package prior to version 13.15.22. The vulnerability arises from incomplete filtering of special Unicode variation selectors (\uFE0F, \uFE0E) in the isLength() function. This flaw causes the function to miscalculate string lengths, allowing applications relying on isLength for input validation to accept strings significantly longer than expected. The improper length validation can result in downstream impacts such as database data truncation, buffer overflows in other system components, or denial-of-service scenarios.
Potential Impact
Applications using the vulnerable versions of validator for input length validation may accept longer strings than intended, leading to potential data truncation in databases, buffer overflow vulnerabilities in other components, or denial-of-service conditions. This can compromise application stability and data integrity.
Mitigation Recommendations
A fix is available in validator version 13.15.22. Users should upgrade to version 13.15.22 or later to address this vulnerability. Patch status is confirmed by the versioning information indicating versions before 13.15.22 are affected.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- snyk
- Date Reserved
- 2025-11-05T16:10:29.370Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6927e863bdf69728cfecb8dd
Added to database: 11/27/2025, 05:57:55 UTC
Last enriched: 08/09/2026, 12:57:21 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 965
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.