CVE-2026-4923Disclosure(pillarjs / path-to-regexp)

LOWCVSS 5.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch pillarjs path-to-regexp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path. Unsafe examples: /*foo-*bar-:baz /*a-:b-*c-:d /x/*a-:b/*c/y Safe examples: /*foo-:bar /*foo-:bar-*baz Patches: Upgrade to version 8.4.0. Workarounds: If you are using multiple wildcard parameters, you can check the regex output with a tool such as https://makenowjust-labs.github.io/recheck/playground/ to confirm whether a path is vulnerable.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1333

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • path-to-regexp

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
path-to-regexp

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-26: 2Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 203-26
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4923 Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulne… https://www.cve.org/CVERecord?id=CVE-2026-4923

    Post summary

    The snippet provides a brief disclosure of CVE-2026-4923, identifying a ReDoS vulnerability linked to multiple wildcards, but lacks PoC, exploit details, or patch information.

    00020178
    56.9K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Medium-severity security fix in path-to-regexp@8.4.0 just released! Patches CVE-2026-4923 — path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-27v5-c462-wpq7

    Post summary

    A security fix for CVE‑2026‑4923, which causes Regex DoS through multiple wildcards, was released for path‑to‑regexp 8.4.0.

    00000107
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppillarjspath-to-regexp-node.js-

Explore more