Skip to main content

Vendor/product archive

pillarjs / path-to-regexp CVEs

Beta · best-effort

3 CVEs tagged to pillarjs / path-to-regexp0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-4926

Published Mar 26, 2026

Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponen…

CVSS 7.5 · High
evidence mentions
21
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-4923

Published Mar 26, 2026

Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability re…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-4867

Published Mar 26, 2026

Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:…

CVSS 7.5 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1