GHSA-27v5-c462-wpq7
path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards
Quick fix
GHSA-27v5-c462-wpq7 — path-to-regexp: upgrade to the fixed version with the command below.
npm install path-to-regexp@8.4.0Details
### Impact
When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path.
**Unsafe examples:**
``` /*foo-*bar-:baz /*a-:b-*c-:d /x/*a-:b/*c/y ```
**Safe examples:**
``` /*foo-:bar /*foo-:bar-*baz ```
### Patches
Upgrade to version `8.4.0`.
### Workarounds
If developers are using multiple wildcard parameters, they can check the regex output with a tool such as https://makenowjust-labs.github.io/recheck/playground/ to confirm whether a path is vulnerable.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-27v5-c462-wpq7[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-4923[ADVISORY]
- https://cna.openjsf.org/security-advisories.html[WEB]
- https://github.com/pillarjs/path-to-regexp[PACKAGE]
- https://makenowjust-labs.github.io/recheck/playground[WEB]