VDB
Sign up
MEDIUM5.9

GHSA-27v5-c462-wpq7

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards

Quick fix

GHSA-27v5-c462-wpq7 — path-to-regexp: upgrade to the fixed version with the command below.

npm install path-to-regexp@8.4.0

Details

### Impact

When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path.

**Unsafe examples:**

``` /*foo-*bar-:baz /*a-:b-*c-:d /x/*a-:b/*c/y ```

**Safe examples:**

``` /*foo-:bar /*foo-:bar-*baz ```

### Patches

Upgrade to version `8.4.0`.

### Workarounds

If developers are using multiple wildcard parameters, they can check the regex output with a tool such as https://makenowjust-labs.github.io/recheck/playground/ to confirm whether a path is vulnerable.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/path-to-regexp
Introduced in: 8.0.0Fixed in: 8.4.0
Fixnpm install path-to-regexp@8.4.0

References