Package
opensearch-dashboards-2-fips
Component
joi
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
The vulnerable code is not present in the bundled joi 14.3.1. CVE-2026-90771 is a prototype replacement in the message-compilation module (lib/messages.js), where a message code named proto replaces the prototype of the compiled messages object; the fix in joi 17.13.8 adds a guard to that module. That module was introduced in the joi 16 line and does not exist in joi 14.3.1, which has no equivalent code. The advisory range is open-ended below 17.13.8, so the scanner matches 14.3.1.
Status