{"id":"CVE-2025-66020","summary":"Valibot has a ReDoS vulnerability in `EMOJI_REGEX`","details":"Valibot helps validate data using a schema. In versions from 0.31.0 to 1.1.0, the EMOJI_REGEX used in the emoji action is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. A short, maliciously crafted string (e.g., \u003c100 characters) can cause the regex engine to consume excessive CPU time (minutes), leading to a Denial of Service (DoS) for the application. This issue has been patched in version 1.2.0.","aliases":["GHSA-vqpr-j7v3-hqw9"],"modified":"2026-08-12T03:51:38.050472721Z","published":"2025-11-26T01:49:38.276Z","database_specific":{"cwe_ids":["CWE-1333"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66020.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66020.json"},{"type":"ADVISORY","url":"https://github.com/open-circle/valibot/security/advisories/GHSA-vqpr-j7v3-hqw9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66020"},{"type":"FIX","url":"https://github.com/open-circle/valibot/commit/cfb799db301a953a0950d5c05a34a3ab121262dc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open-circle/valibot","events":[{"introduced":"1d5f55fdb3fb646f80c2667a37044a7b55341e94"},{"fixed":"cfb799db301a953a0950d5c05a34a3ab121262dc"}],"database_specific":{"extracted_events":[{"introduced":"0.31.0"},{"fixed":"1.2.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v1.3.0-to-json-schema","v1.2.0-to-json-schema","v1.1.0-to-json-schema","v1.1.0","v1.0.0-to-json-schema","v1.0.0-i18n","v1.0.0","v1.0.0-rc.4","v1.0.0-rc.3","v1.0.0-rc.2","v1.0.0-rc.1","v1.0.0-rc.0-to-json-schema","v1.0.0-rc.0-i18n","v1.0.0-rc.0","v1.0.0-beta.15","v1.0.0-beta.14","v1.0.0-beta.5-to-json-schema","v1.0.0-beta.13","v1.0.0-beta.12","v1.0.0-beta.4-to-json-schema","v1.0.0-beta.11","v1.0.0-beta.10","v1.0.0-beta.2-i18n","v1.0.0-beta.9","v1.0.0-beta.8","v1.0.0-beta.7","v1.0.0-beta.6","v1.0.0-beta.3-to-json-schema","v1.0.0-beta.5","v1.0.0-beta.4","v1.0.0-beta.1-i18n","v1.0.0-beta.2-to-json-schema","v1.0.0-beta.1-to-json-schema","v1.0.0-beta.3","v1.0.0-beta.2","v1.0.0-beta.1","v1.0.0-beta.0-i18n","1.0.0-beta.0-to-json-schema","v1.0.0-beta.0","v0.2.1-to-json-schema","v0.42.1","v0.2.0-to-json-schema","v0.42.0","v0.1.1-to-json-schema","v0.1.0-to-json-schema","v0.41.0","v0.40.0","v0.39.0","v0.38.0","v0.37.0","v0.36.0","v0.35.0","v0.34.0","v0.33.3","v0.33.2","v0.33.1","v0.33.0","v0.32.0","v0.31.1","v0.31.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66020.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}