Skip to main content
EPSS 0.5%top 59%

CVE-2025-69873: CWE-1333 Inefficient Regular Expression Complexity in ajv.js ajv

0
Low
VulnerabilityCVE-2025-69873cvecve-2025-69873cwe-1333
Published: 02/11/2026 (02/11/2026, 00:00:00 UTC)
Source: CVE Database V5
Vendor/Project: ajv.js
Product: ajv

Description

ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., "^(a|a)*$") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation. This issue is also fixed in version 6.14.0.

CVSS v3.1

Score 2.9low

Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected software

ajv.js

ajv

Affected versions
>=0 <6.14.0>=7.0.0 <8.17.2

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 13:11:59 UTC

Technical Analysis

CVE-2025-69873 describes a ReDoS vulnerability in ajv before version 8.18.0 when the $data option is enabled. The pattern keyword in JSON schema validation accepts dynamic data via JSON Pointer syntax, which is passed unchecked to the JavaScript RegExp() constructor. An attacker can exploit this by injecting a malicious regex pattern that triggers catastrophic backtracking, causing significant CPU resource consumption and denial of service. The vulnerability requires the $data option to be enabled and the ability to supply crafted input. The vulnerability has been assigned a CVSS v3 score of 7.5 by Red Hat, indicating important severity, although other sources list it as low severity. The vulnerability is fixed in ajv version 8.18.0.

Potential Impact

An attacker able to supply a malicious regular expression pattern when the $data option is enabled can cause the application to become unresponsive due to excessive CPU consumption, resulting in a denial of service. The attack requires the ability to send crafted input to the application using ajv with $data: true. The impact is limited to availability with no confidentiality or integrity impact. The vulnerability can cause prolonged CPU blocking with relatively small payloads.

Mitigation Recommendations

A fix is available in ajv version 8.18.0. Users should upgrade to this or a later version to remediate the vulnerability. If upgrading is not immediately possible, the vendor advisory recommends disabling the $data feature if it is not required. If $data must be used, strict validation of input fields referenced by the pattern keyword should be implemented to ensure only expected and safe characters are accepted.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
mitre
Date Reserved
2026-01-09T00:00:00.000Z
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2025-69873","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13512","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6277","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:16874","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6309","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:9742","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6802","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5807","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19712","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:15091","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:14774","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5910","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5907","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:10093","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6192","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:7314","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6568","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6497","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6567","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5168","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26214","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26211","vendor":"Red Hat"}]

Threat ID: 698cce794b57a58fa1b3e299

Added to database: 02/11/2026, 18:46:17 UTC

Last enriched: 08/17/2026, 13:11:59 UTC

Last updated: 09/10/2026, 22:12:33 UTC

Views: 864

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses