SB2026022657 - Incomplete Filtering of Special Elements in validator.js



SB2026022657 - Incomplete Filtering of Special Elements in validator.js

Published: February 26, 2026

Security Bulletin ID SB2026022657
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Incomplete Filtering of Special Elements (CVE-ID: CVE-2025-12758)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (uFE0F, uFE0E) appearing in a sequence which lead to improper string length calculation. A remote attacker can trick an application into using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer overflows in other system components, or denial-of-service


Remediation

Install update from vendor's website.