Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Oct 27, 2025

This PR contains the following updates:

Package Change Age Confidence
validator 13.11.013.15.22 age confidence

GitHub Vulnerability Alerts

CVE-2025-56200

A URL validation bypass vulnerability exists in validator.js prior to version 13.15.20. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as the delimiter. This parsing difference allows attackers to bypass protocol and domain validation by crafting URLs leading to XSS and Open Redirect attacks.

CVE-2025-12758

Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This can lead to an application using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer overflows in other system components, or denial-of-service.


Release Notes

validatorjs/validator.js (validator)

v13.15.22

Compare Source

Fixes, New Locales and Enhancements

v13.15.20

Compare Source

Fixes, New Locales and Enhancements

v13.15.15

Compare Source

Fixes, New Locales and Enhancements

v13.15.0

Compare Source

New Features / Validators
Fixes, New Locales and Enhancements

v13.12.0

Compare Source

New Features / Validators
Fixes, New Locales and Enhancements

Configuration

📅 Schedule: Branch creation - "" in timezone Australia/Sydney, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot enabled auto-merge (squash) October 27, 2025 16:04
@netlify
Copy link

netlify bot commented Oct 27, 2025

Deploy Preview for timjames ready!

Name Link
🔨 Latest commit 8d84d7c
🔍 Latest deploy log https://app.netlify.com/projects/timjames/deploys/696e716c58c85800080b28e9
😎 Deploy Preview https://deploy-preview-92--timjames.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 28
Accessibility: 100
Best Practices: 83
SEO: 93
PWA: 80
View the detailed breakdown and full score reports

To edit notification comments on pull requests, go to your Netlify project configuration.

@renovate renovate bot force-pushed the renovate/npm-validator-vulnerability branch from 9b69802 to f49adaa Compare November 10, 2025 13:55
@renovate renovate bot force-pushed the renovate/npm-validator-vulnerability branch from f49adaa to 7630076 Compare November 19, 2025 00:44
@renovate renovate bot force-pushed the renovate/npm-validator-vulnerability branch from 7630076 to b894ce6 Compare December 2, 2025 18:47
@renovate renovate bot changed the title chore(deps): update dependency validator to v13.15.20 [security] chore(deps): update dependency validator to v13.15.22 [security] Dec 2, 2025
@renovate renovate bot force-pushed the renovate/npm-validator-vulnerability branch from b894ce6 to c93f5b2 Compare December 3, 2025 18:55
@renovate renovate bot force-pushed the renovate/npm-validator-vulnerability branch 2 times, most recently from cedd9aa to b7dba2f Compare January 7, 2026 02:20
@renovate renovate bot force-pushed the renovate/npm-validator-vulnerability branch from b7dba2f to 769d232 Compare January 8, 2026 19:17
@renovate renovate bot force-pushed the renovate/npm-validator-vulnerability branch from 769d232 to 8d84d7c Compare January 19, 2026 18:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant