HIGH7.5
GHSA-rhx6-c78j-4q9w
path-to-regexp contains a ReDoS
Quick fix
GHSA-rhx6-c78j-4q9w — path-to-regexp: upgrade to the fixed version with the command below.
npm install path-to-regexp@0.1.12Details
### Impact
The regular expression that is vulnerable to backtracking can be generated in versions before 0.1.12 of `path-to-regexp`, originally reported in CVE-2024-45296
### Patches
Upgrade to 0.1.12.
### Workarounds
Avoid using two parameters within a single path segment, when the separator is not `.` (e.g. no `/:a-:b`). Alternatively, you can define the regex used for both parameters and ensure they do not overlap to allow backtracking.
### References
- https://github.com/advisories/GHSA-9wv6-86v2-598j - https://blakeembrey.com/posts/2024-09-web-redos/
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-rhx6-c78j-4q9w[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-52798[ADVISORY]
- https://github.com/pillarjs/path-to-regexp/commit/f01c26a013b1889f0c217c643964513acf17f6a4[WEB]
- https://blakeembrey.com/posts/2024-09-web-redos[WEB]
- https://github.com/pillarjs/path-to-regexp[PACKAGE]
- https://security.netapp.com/advisory/ntap-20250124-0002[WEB]