{"id":"CVE-2016-2537","aliases":["GHSA-f522-ffg8-j8r6"],"url":"https://o3.security/vulnerability/CVE-2016-2537","summary":"Regular Expression Denial of Service in is-my-json-valid","details":"The is-my-json-valid package before 2.12.4 for Node.js has an incorrect exports['utc-millisec'] regular expression, which allows remote attackers to cause a denial of service (blocked event loop) via a crafted string.","published":"2016-02-23T05:59:01.217Z","modified":"2026-07-08T12:05:54.573650Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"is-my-json-valid","fixedVersion":"2.12.4"}],"fix":{"url":"https://github.com/mafintosh/is-my-json-valid/commit/eca4beb21e61877d76fdf6bea771f72f39544d9b","label":"mafintosh/is-my-json-valid@eca4beb"},"references":[{"type":"ADVISORY","url":"https://nodesecurity.io/advisories/76"},{"type":"FIX","url":"https://github.com/mafintosh/is-my-json-valid/commit/eca4beb21e61877d76fdf6bea771f72f39544d9b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:05:54.573650Z"}}