Junglewise Threat Intelligence

CVE-2026-4867: pillarjs path-to-regexp ReDoS via multiple route parameters

CVE-2026-4867 · Severity: low · CVSS 3.1 · Published 2026-03-27

Technologies: path-to-regexp (npm). Vendors: npm.

Executive brief

path-to-regexp is vulnerable to Regular Expression Denial of Service (ReDoS) when three or more parameters are used within a single URL segment.

Affected products

  • npm path-to-regexp

Related threats