Skip to main content
Vulnerability Database/CVE-2026-59952

CVE-2026-59952: Valibot DOS Vulnerability

CVE-2026-59952 is a denial of service flaw in Valibot that causes TypeError crashes when flatten() processes attacker-controlled object keys. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-59952 Overview

CVE-2026-59952 affects Valibot, a schema-based data validation library for TypeScript and JavaScript. Versions prior to 1.4.2 throw a TypeError inside the flatten() helper when validation issues contain attacker-controlled object keys such as toString, valueOf, or hasOwnProperty. The flaw is reachable through normal record() validation flows. Applications that validate user-controlled objects with record() and return structured validation errors via flatten() can have their request path crash instead of returning a proper error response. This is not a global prototype pollution issue — the impact is limited to availability and error handling [CWE-755: Improper Handling of Exceptional Conditions].

Critical Impact

Remote unauthenticated attackers can trigger an unhandled TypeError in API endpoints that validate arbitrary object payloads with Valibot's record() schema, crashing the request path.

Affected Products

  • Valibot versions prior to 1.4.2
  • Applications using Valibot's record() schema with flatten() for API error responses
  • Node.js and JavaScript runtime services depending on the affected Valibot versions

Discovery Timeline

  • 2026-07-30 - CVE-2026-59952 published to NVD
  • 2026-07-30 - Last updated in NVD database

Technical Details for CVE-2026-59952

Vulnerability Analysis

Valibot's record() schema validates objects whose keys and values match provided schemas. The implementation intentionally filters the dangerous keys __proto__, prototype, and constructor to prevent prototype pollution. However, it still accepts other own keys that collide with inherited Object.prototype methods, such as toString, valueOf, and hasOwnProperty.

When the key or value schema rejects such an entry, Valibot constructs an issue path that includes the offending key. Passing those issues to the documented flatten() helper causes flatErrors.nested[dotPath] to resolve to the inherited prototype method rather than an own error array. The helper then calls .push(...) on that function reference, which throws a TypeError and aborts execution.

Root Cause

The root cause is unchecked property access on an object used as a map. The flatten() helper checked if (flatErrors.nested![dotPath]), which returns truthy for inherited properties. Because functions like toString exist on every object via the prototype chain, the check falsely concludes an entry exists and attempts to invoke .push() on a function reference [CWE-755].

Attack Vector

An unauthenticated attacker submits a JSON body containing an object with a key that shadows an Object.prototype member — for example, {"toString": "invalid-value"} — to any API endpoint that validates the payload with record() and formats errors with flatten(). Validation of the offending value fails, generating an issue path containing toString, and the subsequent flatten call throws a TypeError.

typescript
// Security patch in library/src/methods/flatten/flatten.ts
// fix: handle keys that collide with Object.prototype in flatten and merge (#1522)
           // @ts-expect-error
           flatErrors.nested = {};
         }
-        if (flatErrors.nested![dotPath]) {
+        if (Object.prototype.hasOwnProperty.call(flatErrors.nested, dotPath)) {
           flatErrors.nested![dotPath]!.push(issue.message);
         } else {
           // @ts-expect-error

Source: GitHub Commit 1bd01c3

A parallel fix applies to the intersect merge utility, which had the same unsafe in check:

typescript
// Security patch in library/src/schemas/intersect/utils/_merge/_merge.ts
       // Deeply merge entries of `value2` into `nextValue`
       for (const key in value2) {
-        // @ts-expect-error
-        if (key in value1) {
+        if (Object.prototype.hasOwnProperty.call(value1, key)) {
           // @ts-expect-error
           const dataset = _merge(value1[key], value2[key]);

Source: GitHub Commit 1bd01c3

Detection Methods for CVE-2026-59952

Indicators of Compromise

  • Unhandled TypeError exceptions containing text such as .push is not a function in application error logs.
  • Repeated 500-class HTTP responses correlated with request bodies containing keys like toString, valueOf, hasOwnProperty, isPrototypeOf, or propertyIsEnumerable.
  • Increased request-handler crash rates or worker restarts following inbound JSON payloads with prototype-named keys.

Detection Strategies

  • Perform a dependency inventory across Node.js services and identify any package with valibot at a version earlier than 1.4.2.
  • Static-analyze application code for calls to flatten() following safeParse or parse on a record() schema handling untrusted input.
  • Enable structured logging on unhandled promise rejections and uncaught exceptions inside HTTP middleware to surface abnormal validator failures.

Monitoring Recommendations

  • Alert on HTTP 5xx spikes originating from validation middleware routes.
  • Monitor request bodies at the WAF or API gateway for prototype-named top-level or nested keys prior to reaching application code.
  • Track Node.js process restarts and event-loop crashes to detect crash-based denial-of-service attempts.

How to Mitigate CVE-2026-59952

Immediate Actions Required

  • Upgrade Valibot to version 1.4.2 or later across all services and rebuild dependent artifacts.
  • Audit application code paths that call flatten() on results produced from record() schemas processing untrusted input.
  • Deploy request-level filtering at the API gateway or WAF to reject payloads containing prototype-named keys until the patch is applied.

Patch Information

The issue is fixed in Valibot 1.4.2. The patch replaces the unsafe truthiness check with Object.prototype.hasOwnProperty.call(...) in both library/src/methods/flatten/flatten.ts and library/src/schemas/intersect/utils/_merge/_merge.ts. See the GitHub Security Advisory GHSA-5qjj-4xww-7phc, the GitHub Pull Request #1522, and the GitHub Release v1.4.2 for full details.

Workarounds

  • Wrap flatten() invocations in try/catch blocks to return a controlled error response instead of crashing the request handler.
  • Pre-validate incoming object keys and reject requests whose keys match Object.prototype members before invoking Valibot.
  • Use Object.create(null) or Map instances internally when routing validation output, avoiding prototype-chain lookups.
bash
# Upgrade Valibot to the patched release
npm install valibot@^1.4.2

# Verify the installed version
npm ls valibot

# Optional: audit all workspaces for outdated versions
npm audit --production

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.