path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Atlassian Bitbucket | — | Upgrade Atlassian Bitbucket to the latest version | Mar 19, 2025 | Mar 18, 2025 |
| Debian | — | No solution existsUpgrade node-path-to-regexp | May 15, 2025 | Sep 9, 2024 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Sep 9, 2024 |
| Redhat Openshift | — | Upgrade rhcos | Aug 17, 2026 | Sep 9, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 9, 2024 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.1.7Upgrade Splunk Enterprise to version 9.3.2Upgrade Splunk Enterprise to version 9.2.4 | Sep 30, 2025 | Sep 9, 2024 |
| Suse | — | Upgrade velociraptorUpgrade system-user-velociraptorUpgrade velociraptor-client | Dec 5, 2025 | Oct 14, 2024 |
| Ubuntu | — | Upgrade node-path-to-regexp (Ubuntu Pro) | May 25, 2026 | May 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub