CVE-2022-31147 is a regular expression denial-of-service vulnerability in the jQuery Validation Plugin (jquery-validation). Versions prior to 1.19.5 are affected. The flaw occurs in the url2 validation method, where attacker-controlled input can trigger excessive backtracking in a regular expression and consume disproportionate processing time. The issue resulted from an incomplete fix for CVE-2021-43306. Successful exploitation can cause the application or client-side validation logic using the vulnerable method to become unresponsive or significantly degraded while processing crafted input.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit and a detailed manual testing guide for CVE-2022-31147, a path traversal vulnerability in the matthiasmullie/minify library. The repository contains two files: a comprehensive README with usage instructions and background, and a Python script (cve-2022-31147_poc.py) that automates the exploitation process. The script generates a variety of traversal payloads (with different depths and encodings) and sends them to a user-specified minify endpoint, attempting to read arbitrary files from the server. It analyzes responses for known markers of sensitive files (e.g., /etc/passwd or win.ini) to determine if exploitation was successful. The README also provides manual curl commands for testing and emphasizes safe, authorized use. The exploit targets web applications exposing the vulnerable minify endpoint and is effective against both Linux and Windows targets. The overall structure is clear and focused on practical exploitation and validation of the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.