{"id":"CVE-2026-4867","aliases":["CVE-2024-45296","GHSA-37ch-88jc-xwx2","GHSA-9wv6-86v2-598j"],"url":"https://o3.security/vulnerability/CVE-2026-4867","summary":"path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters","details":"Impact:\n\nA bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in path-to-regexp@0.1.12 only prevents ambiguity for two parameters. With three or more, the generated lookahead does not block single separator characters, so capture groups overlap and cause catastrophic backtracking.\n\nPatches:\n\nUpgrade to path-to-regexp@0.1.13\n\nCustom regex patterns in route definitions (e.g., /:a-:b([^-/]+)-:c([^-/]+)) are not affected because they override the default capture group.\n\nWorkarounds:\n\nAll versions can be patched by providing a custom regular expression for parameters after the first in a single segment. As long as the custom regular expression does not match the text before the parameter, you will be safe. For example, change /:a-:b-:c to /:a-:b([^-/]+)-:c([^-/]+).\n\nIf paths cannot be rewritten and versions cannot be upgraded, another alternative is to limit the URL length.","published":"2026-03-26T16:16:25.501Z","modified":"2026-07-15T01:48:49.500361337Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"path-to-regexp","fixedVersion":"0.1.13"}],"fix":null,"references":[{"type":"WEB","url":"https://blakeembrey.com/posts/2024-09-web-redos"},{"type":"ADVISORY","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4867.json"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9wv6-86v2-598j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4867"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:49.500361337Z"}}