CVE detail
CVE-2025-12758
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This can lead to an application using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer overflows in other system components, or denial-of-service.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 9.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- http://seclists.org/fulldisclosure/2026/Jan/27seclists.org
No excerpt available.
Exploitseclists.orgNov 27, 2025, 5:16 AM - https://security.snyk.io/vuln/SNYK-JS-VALIDATOR-13653476security.snyk.io
No excerpt available.
Exploitsecurity.snyk.ioNov 27, 2025, 5:16 AM - https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-14152011security.snyk.io
No excerpt available.
Exploitsecurity.snyk.ioNov 27, 2025, 5:16 AM No excerpt available.
Exploitgithub.comNov 27, 2025, 5:16 AMNo excerpt available.
Exploitgist.github.comNov 27, 2025, 5:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-48784CVSS 5.1 · Medium
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strt…
- CVE-2026-42926CVSS 6.3 · Medium
When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and…
- CVE-2025-47779CVSS 7.7 · High
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-a…
- CVE-2025-27110CVSS 7.9 · High
Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional…
- CVE-2024-48909CVSS 2.0 · Low
SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have ena…
- CVE-2023-25608CVSS 5.5 · Medium
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-W2 7.2.0 through 7.2.1, 7.0.3 through 7.0.5…