CVE-2026-5986 is a regular expression denial-of-service vulnerability in the Zod jsVideoUrlParser library up to version 0.5.1, specifically affecting the getTime function in lib/util.js. The vulnerability arises from inefficient regex complexity when processing the timestamp argument, making it susceptible to exploitation by malicious input. The vulnerability has a CVSS score of 5.3 (Medium) with a network-based attack vector requiring no authentication or user interaction. While the attack complexity is low and can be initiated remotely, the impact is limited to availability, causing denial of service without affecting confidentiality or integrity. The exploit code has been publicly disclosed, creating a potential attack surface. However, exploitation appears limited at present, as the vulnerability is not listed on the Known Exploited Vulnerabilities catalog and the project maintainers have not yet responded to early notification. The FAUCET Risk Score of 32.0 and low EPSS score suggest this remains a lower-priority threat in the broader threat landscape, though organizations using affected versions should monitor for patches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Zod | JsVideoUrlParser | 0.5.0, 0.5.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.