CVE-2025-69873: ajv 8.17.1 ReDoS via $data regex injection
CVE-2025-69873 Published on February 11, 2026
ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., "^(a|a)*$") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation. This issue is also fixed in version 6.14.0.
Vulnerability Analysis
CVE-2025-69873 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. An automatable proof of concept (POC) exploit exists. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Types
What is a ReDoS Vulnerability?
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles. Some regular expression engines have a feature called "backtracking". If the token cannot match, the engine "backtracks" to a position that may result in a different token that can match. Backtracking becomes a weakness if all of these conditions are met:
CVE-2025-69873 has been classified to as a ReDoS vulnerability or weakness.
What is a Resource Exhaustion Vulnerability?
The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVE-2025-69873 has been classified to as a Resource Exhaustion vulnerability or weakness.
Products Associated with CVE-2025-69873
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2025-69873 are published in these products:
Affected Versions
ajv.js ajv:- Before 6.14.0 is affected.
- Version 7.0.0 and below 8.17.2 is affected.
- Version 0:2.5.20260422-2.el8ap and below * is unaffected.
- Version 0:2.5.20260422-2.el9ap and below * is unaffected.
- Version 0:2.6.7-1.el9ap and below * is unaffected.
- Version 0:7.3.18-3.GA_redhat_00001.1.el7eap and below * is unaffected.
- Version 1778508956 and below * is unaffected.
- Version 1774243862 and below * is unaffected.
- Version 1776784286 and below * is unaffected.
- Version 1775140647 and below * is unaffected.
- Version 1783502765 and below * is unaffected.
- Version 1783502438 and below * is unaffected.
- Version 1784194938 and below * is unaffected.
- Version 1784194574 and below * is unaffected.
- Version 1784126822 and below * is unaffected.
- Version 1784127736 and below * is unaffected.
- Version 1774282136 and below * is unaffected.
- Version 1779189627 and below * is unaffected.
- Version 1778473763 and below * is unaffected.
- Version 1778666987 and below * is unaffected.
- Version 1778036641 and below * is unaffected.
- Version 1777994844 and below * is unaffected.
- Version 1774452649 and below * is unaffected.
- Version 1774474908 and below * is unaffected.
- Version 1776675872 and below * is unaffected.
- Version 1783676191 and below * is unaffected.
- Version 1783929816 and below * is unaffected.
- Version 1784094353 and below * is unaffected.
- Version 1784093953 and below * is unaffected.
- Version 1784094943 and below * is unaffected.
- Version 1783676585 and below * is unaffected.
- Version 1783676649 and below * is unaffected.
- Version 1783676675 and below * is unaffected.
- Version 1784094299 and below * is unaffected.
- Version 1784094725 and below * is unaffected.
- Version 1783676820 and below * is unaffected.
- Version 1783676883 and below * is unaffected.
- Version 1783676894 and below * is unaffected.
- Version 1784095175 and below * is unaffected.
- Version 1783676977 and below * is unaffected.
- Version 1784093503 and below * is unaffected.
- Version 1783677297 and below * is unaffected.
- Version 1783677345 and below * is unaffected.
- Version 1783677533 and below * is unaffected.
- Version 1783684360 and below * is unaffected.
- Version 1783684068 and below * is unaffected.
- Version 1784054582 and below * is unaffected.
- Version 1784054606 and below * is unaffected.
- Version 1784055295 and below * is unaffected.
- Version 1783684603 and below * is unaffected.
- Version 1783684668 and below * is unaffected.
- Version 1783684667 and below * is unaffected.
- Version 1784054873 and below * is unaffected.
- Version 1783684707 and below * is unaffected.
- Version 1784055589 and below * is unaffected.
- Version 1783684779 and below * is unaffected.
- Version 1783684831 and below * is unaffected.
- Version 1783684839 and below * is unaffected.
- Version 1784055533 and below * is unaffected.
- Version 1784055558 and below * is unaffected.
- Version 1784056134 and below * is unaffected.
- Version 1783685128 and below * is unaffected.
- Version 1783685129 and below * is unaffected.
- Version 1783685375 and below * is unaffected.
- Version 1783667125 and below * is unaffected.
- Version 1783666755 and below * is unaffected.
- Version 1784054598 and below * is unaffected.
- Version 1784055387 and below * is unaffected.
- Version 1784055726 and below * is unaffected.
- Version 1783667517 and below * is unaffected.
- Version 1783667577 and below * is unaffected.
- Version 1783667611 and below * is unaffected.
- Version 1784055020 and below * is unaffected.
- Version 1783667641 and below * is unaffected.
- Version 1784055586 and below * is unaffected.
- Version 1783667790 and below * is unaffected.
- Version 1783667859 and below * is unaffected.
- Version 1783667875 and below * is unaffected.
- Version 1783667869 and below * is unaffected.
- Version 1783667877 and below * is unaffected.
- Version 1784055576 and below * is unaffected.
- Version 1784055244 and below * is unaffected.
- Version 1784055382 and below * is unaffected.
- Version 1783668266 and below * is unaffected.
- Version 1783668288 and below * is unaffected.
- Version 1783669219 and below * is unaffected.
- Version 1774448966 and below * is unaffected.
- Version 1774476526 and below * is unaffected.
- Version 1775512163 and below * is unaffected.
- Version 1775169219 and below * is unaffected.
- Version 1775069491 and below * is unaffected.
- Version 1775169226 and below * is unaffected.
- Version 1773936323 and below * is unaffected.
- Version 1781247025 and below * is unaffected.
- Version 1781181673 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.