Path-to-regexp
This hub aggregates every CVE we track for Path-to-regexp, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
5
CVEs tracked
0
Critical
4
High
0
In CISA KEV
Severity distribution
HIGH4MEDIUM1
Monthly trend
1
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
3
0
0
0
0
0
2024-092026-08
Latest CVEs
The 5 most recently published vulnerabilities affecting Path-to-regexp.
- CVE-2026-4923path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards5.9
- CVE-2026-4926path-to-regexp vulnerable to Denial of Service via sequential optional groups7.5
- CVE-2026-4867path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters7.5
- CVE-2024-52798path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x7.5
- CVE-2024-45296path-to-regexp outputs backtracking regular expressions7.5
Product normalization is registry-driven with AI assist and human review. How it works