Incomplete Filtering of Special Elements in validator.js - CVE-2025-12758

 

Incomplete Filtering of Special Elements in validator.js - CVE-2025-12758

Published: February 26, 2026


Vulnerability identifier: #VU123307
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-12758
CWE-ID: CWE-791
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (uFE0F, uFE0E) appearing in a sequence which lead to improper string length calculation. A remote attacker can trick an application into using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer overflows in other system components, or denial-of-service


Affected software

validator.js
watsonx.data
watsonx Orchestrate Developer Edition
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Automation Assets in IBM Cloud Pak for Integration (CP4I)

How to mitigate CVE-2025-12758

Install updates from vendor's website.

validator.js - update to 13.15.22
watsonx Orchestrate Developer Edition - update to 2.3.0
watsonx.data - update to 2.3.1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 4.3.1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - update to 16.1.0.20

External References

Related Security Bulletins