Skip to content

fix(pattern): use configured RegExp engine with $data keyword to mitigate ReDoS attacks (CVE-2025-69873)#2586

Merged
epoberezkin merged 3 commits intomasterfrom
KsAkira10-fix/cve-2025-69873-redos-attack
Feb 14, 2026
Merged

fix(pattern): use configured RegExp engine with $data keyword to mitigate ReDoS attacks (CVE-2025-69873)#2586
epoberezkin merged 3 commits intomasterfrom
KsAkira10-fix/cve-2025-69873-redos-attack

Conversation

@epoberezkin
Copy link
Member

@epoberezkin epoberezkin commented Feb 14, 2026

No description provided.

@epoberezkin epoberezkin merged commit 720a23f into master Feb 14, 2026
4 checks passed
@epoberezkin epoberezkin deleted the KsAkira10-fix/cve-2025-69873-redos-attack branch February 14, 2026 00:27
vadyvas pushed a commit to Redocly/ajv that referenced this pull request Feb 27, 2026
…gate ReDoS attacks (CVE-2025-69873) (ajv-validator#2586)

* fix(pattern): address CVE-2025-69873 by implementing safeguards against ReDoS attacks in pattern validation

* remove console.log

* remove Node.js 16 CI build

---------

Co-authored-by: Lucas Akira Uehara <80917717@telefonicati.onmicrosoft.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants