VDB
Sign up
HIGH7.5

GHSA-rhx6-c78j-4q9w

path-to-regexp contains a ReDoS

Quick fix

GHSA-rhx6-c78j-4q9w — path-to-regexp: upgrade to the fixed version with the command below.

npm install path-to-regexp@0.1.12

Details

### Impact

The regular expression that is vulnerable to backtracking can be generated in versions before 0.1.12 of `path-to-regexp`, originally reported in CVE-2024-45296

### Patches

Upgrade to 0.1.12.

### Workarounds

Avoid using two parameters within a single path segment, when the separator is not `.` (e.g. no `/:a-:b`). Alternatively, you can define the regex used for both parameters and ensure they do not overlap to allow backtracking.

### References

- https://github.com/advisories/GHSA-9wv6-86v2-598j - https://blakeembrey.com/posts/2024-09-web-redos/

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/path-to-regexp
Introduced in: 0Fixed in: 0.1.12
Fixnpm install path-to-regexp@0.1.12

References