CVE-2025-12758Disclosure(validator_project / validator)

LOWCVSS 7.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This can lead to an application using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer overflows in other system components, or denial-of-service.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-792CWE-172

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • validator

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Patch: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
validator

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-28: 1Mentions · 2026-01-30: 1Mentions · 2026-05-19: 1PoC Mentioned / Linked · 2026-01-28: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-30: 101-2801-3005-19
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-281
Disclosure1
2026-01-301
Disclosure1
2026-05-191
Patch1
Full discourse3 posts
  • Autumn Good@autumn_good_35
    Patch

    CVE-2025-12758 CVE-2025-64945 CVE-2026-27699 CVE-2026-27601 CVE-2026-27903 CVE-2026-27904 CVE-2026-26996 CVE-2026-25639 HPESBNW05056 rev.1 - HPE Unified OSS Console Assurance Monitoring (UOCAM), Multiple Vulnerabilities https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05056en_us&docLocale=en_US

    Post summary

    The text lists multiple CVEs and directs readers to an HPE support page, indicating that vendor advisories (patches or mitigations) are likely available, but no concrete details are provided in the snippet.

    000001.5K
    6.9K followersView on X
  • Yosun@NusoyYosu
    Disclosure

    CVE-2025-12758: Unicode Variation Selectors Bypass in 'validator' library (isLength) https://dev.to/mark0_617b45cda9782a/cve-2025-12758-unicode-variation-selectors-bypass-in-validator-library-islength-ghh

    Post summary

    The text announces CVE‑2025‑12758 as a Unicode Variation Selector bypass affecting the isLength function of the validator library, without mentioning exploits, PoC or patches.

    0000046
    9 followersView on X
  • Karol Wrótniak@karol_wrotniak
    Disclosure

    Is your input validation truly secure? 🛡️🧐 I just published a new blog post about CVE-2025-12758 — a bug I found in the validator.js library. 🕵️‍♂️ By using emoji variant selectors, it was bypass length checks and inject an infinite text. https://www.thedroidsonroids.com/blog/when-zero-width-isnt-zero #security #js #cve

    Post summary

    The author reports a newly discovered bug in validator.js, explains how emoji variant selectors bypass length checks to inject infinite text, and shares a blog post with more details.

    0000071
    53 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvalidator_projectvalidator-node.js-

Explore more