
🚨 High-severity security fix in path-to-regexp@8.4.0 just released! Patches CVE-2026-4926 — path-to-regexp vulnerable to Denial of Service via sequential optional groups https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-j3q9-mxjg-w52f
Post summary
A high‑severity patch is available for CVE‑2026‑4926, fixing a Denial of Service vulnerability in path-to-regexp through sequential optional groups.



