{"id":"CVE-2026-90771","summary":"joi before 17.13.8 and 18.2.9 Prototype Pollution via messages","details":"joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.","modified":"2026-09-15T03:48:23.841905965Z","published":"2026-09-13T10:45:42.498Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-1321"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90771.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90771.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90771"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/joi-before-17.13.8-and-18.2.9-prototype-pollution-via-messages"},{"type":"REPORT","url":"https://github.com/hapijs/joi/issues/3150"},{"type":"FIX","url":"https://github.com/hapijs/joi/commit/5b8333c9177e08b4ef4ed02903c2d657084e7afb"},{"type":"PACKAGE","url":"https://github.com/hapijs/joi"},{"type":"ARTICLE","url":"https://github.com/hapijs/joi/blob/v18.2.8/lib/messages.js"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hapijs/joi","events":[{"introduced":"b0356892c9342d340eab73f11d4086c0ceeebb9a"},{"introduced":"55b0096347c8bd963a9fc04060985344bb69f9ad"},{"fixed":"4ae6af96f7990fdb336aa8ad7dee5e9f847d084a"},{"fixed":"fc3f3bcb58ce7c3d2e7645bc7b17f012a2e7649b"},{"fixed":"5b8333c9177e08b4ef4ed02903c2d657084e7afb"}],"database_specific":{"extracted_events":[{"introduced":"16.0.0"},{"fixed":"17.13.8"},{"introduced":"18.0.0"},{"fixed":"18.2.9"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v17.13.7","v18.2.8","v18.2.7","v18.2.6","v17.13.6","v18.2.5","v17.13.5","v18.2.4","v17.13.4","v18.2.3","v18.2.2","v17.13.3","v18.2.1","v18.2.0","v18.1.2","v18.1.1","v18.1.0","v18.0.2","v18.0.1","v18.0.0","v17.13.2","v17.13.1","v17.13.0","v17.12.3","v17.12.2","v17.12.1","v17.12.0","v17.11.1","v17.11.0","v17.10.2","v17.10.1","v17.10.0","v17.9.2","v17.9.1","v17.9.0","v17.8.4","v17.8.3","v17.8.2","v17.8.1","v17.8.0","v17.7.1","v17.7.0","v17.6.4","v17.6.3","v17.6.2","v17.6.1","v17.6.0","v17.5.0","v17.4.3","v17.4.2","v17.4.1","v17.4.0","v17.3.0","v17.2.1","v17.2.0","v16.1.8","v17.1.1","v17.1.0","v17.0.2","v17.0.1","v17.0.0","v16.1.7","v16.1.6","v16.1.5","v16.1.4","v16.1.3","v16.1.2","v16.1.1","v16.1.0","v16.0.1","v16.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90771.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}