Back

HIGH

path-to-regexp outputs backtracking regular expressions

Published Sep 9, 2024

Description

path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 9, 2024
Updated Jan 24, 2025
Reserved Aug 26, 2024
CISA Vulnrichment
Updated Sep 9, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 9, 2024
ENISA EUVD
Assigner GitHub_M
Published Sep 9, 2024
Updated Jan 24, 2025
Exploited since n/a
EUVD-2024-2764 GHSA-9WV6-86V2-598J