CVE-2026-4926Patch(pillarjs / path-to-regexp)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pillarjs path-to-regexp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service. Patches: Fixed in version 8.4.0. Workarounds: Limit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-1333

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • path-to-regexp

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-26); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
path-to-regexp

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-26: 2Mentions · 2026-03-31: 1Mentions · 2026-06-01: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-06-01: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-31: 103-2603-3106-01
Signal classification3 categories
Patch
250.0%
General
125.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-262
General1Patch1
2026-03-311
Disclosure1
2026-06-011
Patch1
Full discourse4 posts
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in path-to-regexp@8.4.0 just released! Patches CVE-2026-4926 — path-to-regexp vulnerable to Denial of Service via sequential optional groups https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-j3q9-mxjg-w52f

    Post summary

    A high‑severity patch is available for CVE‑2026‑4926, fixing a Denial of Service vulnerability in path-to-regexp through sequential optional groups.

    01030437
    5.6K followersView on X
  • MX3 Dev@Mx3Dev
    Patch

    @mem0ai More CVE remediations → langsmith → ^0.6.0 (CVE-2026-45134) → minimatch → ^3.1.3 / ^5.1.8 / ^9.0.7 (3 CVEs) → picomatch → ^2.3.2 (CVE-2026-33671) → path-to-regexp → ^8.4.0 (CVE-2026-4926) → glob → ^10.5.0 (CVE-2025-64756)

    Post summary

    The tweet provides updated package versions that remediate several CVEs, focusing on patching rather than exploitation or vulnerability details.

    1000061
    106 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A Denial of Service vulnerability (CVE-2026-4926) affects the `path-to-regexp` library. Crafted input can lead to service unavailability. Monitor for official fixes. #DoS #javascript #infosec https://www.pulsepatch.io/posts/cve-2026-4926-path-to-regexp-denial-of-service

    Post summary

    The tweet announces a newly disclosed DoS vulnerability (CVE‑2026‑4926) in the path‑to‑regexp JavaScript library that can be triggered by crafted input, urging users to watch for vendor patches.

    0000019
    6 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4926 Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex gr… https://www.cve.org/CVERecord?id=CVE-2026-4926

    Post summary

    The post merely outlines the nature of CVE-2026-4926—an issue where multiple optional regex groups create a problematic expression—without providing any PoC, exploit, patch, or evidence of real‑world use.

    00000201
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppillarjspath-to-regexp-node.js-

Explore more