Executive brief
path-to-regexp is vulnerable to Regular Expression Denial of Service (ReDoS) when three or more parameters are used within a single URL segment.
Affected products
- npm path-to-regexp
Junglewise Threat Intelligence
CVE-2026-4867 · Severity: low · CVSS 3.1 · Published 2026-03-27
Technologies: path-to-regexp (npm). Vendors: npm.
path-to-regexp is vulnerable to Regular Expression Denial of Service (ReDoS) when three or more parameters are used within a single URL segment.