Ajv.Js maintains a JSON schema validation library that, while narrowly scoped to a single product, is widely embedded across JavaScript and Node.js applications as a foundational dependency. The durable signal in its disclosures centers on prototype-pollution vulnerabilities arising from the library's object-manipulation logic during schema validation, a weakness class characteristic of JavaScript runtime environments. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ajv.Js over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-69873HIGH ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtim | Feb 11, 2026 | 7.5 | 31 | NO | NO |
CVE-2020-15366MEDIUM An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code b | Jul 15, 2020 | 5.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ajv.Js.
Media articles that mention a CVE ID that affects a product developed by Ajv.Js — matched by CVE ID, not by vendor name.