CVE-2026-4867Patch(pillarjs / path-to-regexp)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pillarjs path-to-regexp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in [email protected] only prevents ambiguity for two parameters. With three or more, the generated lookahead does not block single separator characters, so capture groups overlap and cause catastrophic backtracking. Patches: Upgrade to [email protected] Custom regex patterns in route definitions (e.g., /:a-:b([^-/]+)-:c([^-/]+)) are not affected because they override the default capture group. Workarounds: All versions can be patched by providing a custom regular expression for parameters after the first in a single segment. As long as the custom regular expression does not match the text before the parameter, you will be safe. For example, change /:a-:b-:c to /:a-:b([^-/]+)-:c([^-/]+). If paths cannot be rewritten and versions cannot be upgraded, another alternative is to limit the URL length.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1333

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • path-to-regexp

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
path-to-regexp

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-26: 1Mentions · 2026-03-29: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-29: 103-2603-29
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-261
Patch1
2026-03-291
General1
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-4867 Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For … https://www.cve.org/CVERecord?id=CVE-2026-4867

    Post summary

    The message gives a concise impact description of CVE‑2026‑4867, highlighting a bad regex generation condition, but does not provide PoC, exploit, patch, or active exploitation data.

    0001074
    56.9K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in path-to-regexp@0.1.13 just released! Patches CVE-2026-4867 — regular Expression Denial of Service via multiple route parameters https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-37ch-88jc-xwx2

    Post summary

    A high‑severity CVE‑2026‑4867 affecting path‑to‑regexp has been patched in a new release, with the advisory noting an expression DoS via multiple parameters but no PoC, exploit code, or active exploitation reported.

    00000101
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppillarjspath-to-regexp-node.js-

Explore more