Junglewise Threat Intelligence

CVE-2024-45296: path-to-regexp ReDoS via backtracking regular expressions

CVE-2024-45296 · Severity: low · CVSS 3.1 · Published 2024-09-09

Vendors: Pillarjs.

Executive brief

path-to-regexp is a routing library that converts URL paths into regular expressions for web applications. When two parameters are placed in a single segment (e.g., /:a-:b), the generated regex uses catastrophic backtracking that can be exploited to cause a denial-of-service by blocking the JavaScript event loop, making the application unresponsive to legitimate requests.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) caused by inefficient regex patterns generated when multiple parameters are separated by non-period characters within a single URL segment. Path patterns like /:a-:b generate regex like /^\/([^\/]+?)-([^\/]+?)\/?$/, which exhibits catastrophic backtracking. An attacker can exploit this by crafting a URL such as /a{'-a'.repeat(8000)}/a that triggers exponential regex backtracking. Since JavaScript regex matching runs on the main thread, this blocks the event loop and causes severe latency degradation (up to 1000x performance penalty). Patches are available in versions 0.1.10, 1.9.0, 3.3.0, 6.3.0, and 8.0.0; version 8.0.0 removes the vulnerable features entirely.

Affected products

  • pillarjs path-to-regexp <0.1.10, >=0.2.0 <1.9.0, >=2.0.0 <3.3.0, >=4.0.0 <6.3.0, >=7.0.0 <8.0.0

CVE identifiers

  • CVE-2024-45296
  • CVE-2026-4867

Timeline

  • 2024-09-09: disclosed: Advisory published

References