{"id":"CVE-2024-52798","aliases":["GHSA-rhx6-c78j-4q9w"],"url":"https://o3.security/vulnerability/CVE-2024-52798","summary":"path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x","details":"### Impact\n\nThe regular expression that is vulnerable to backtracking can be generated in versions before 0.1.12 of `path-to-regexp`, originally reported in CVE-2024-45296\n\n### Patches\n\nUpgrade to 0.1.12.\n\n### Workarounds\n\nAvoid using two parameters within a single path segment, when the separator is not `.` (e.g. no `/:a-:b`). Alternatively, you can define the regex used for both parameters and ensure they do not overlap to allow backtracking.\n\n### References\n\n- https://github.com/advisories/GHSA-9wv6-86v2-598j\n- https://blakeembrey.com/posts/2024-09-web-redos/","published":"2024-12-05T22:45:42.774Z","modified":"2026-08-12T03:51:28.729659972Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"path-to-regexp","fixedVersion":"0.1.12"}],"fix":{"url":"https://github.com/pillarjs/path-to-regexp/commit/f01c26a013b1889f0c217c643964513acf17f6a4","label":"pillarjs/path-to-regexp@f01c26a"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52798.json"},{"type":"ADVISORY","url":"https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-rhx6-c78j-4q9w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52798"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250124-0002/"},{"type":"FIX","url":"https://github.com/pillarjs/path-to-regexp/commit/f01c26a013b1889f0c217c643964513acf17f6a4"},{"type":"WEB","url":"https://blakeembrey.com/posts/2024-09-web-redos"},{"type":"PACKAGE","url":"https://github.com/pillarjs/path-to-regexp"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20250124-0002"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:28.729659972Z"}}