PT-2025-48121 · Valibot+1 · Valibot+1

Published

2025-11-26

·

Updated

2026-04-21

·

CVE-2025-66020

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Valibot versions 0.31.0 through 1.1.0
Description Valibot is a data validation library that utilizes schemas. Versions from 0.31.0 to 1.1.0 contain a Regular Expression Denial of Service (ReDoS) issue within the EMOJI REGEX used in the emoji action. A specially crafted, short string (less than 100 characters) can cause the regular expression engine to consume excessive CPU time, potentially leading to a Denial of Service (DoS) condition for the application.
Recommendations Update to version 1.2.0 or later.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2025-66020
GHSA-VQPR-J7V3-HQW9

Affected Products

Confluence
Valibot