Vulnerabilities/

path-to-regexp contains a ReDoS

Severity:
High

Description

The regular expression that is vulnerable to backtracking can be generated in versions before 0.1.12 of path-to-regexp, originally reported in CVE-2024-45296

Recommendation

Update the path-to-regexp package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
path-to-regexp
Anything's wrong? Let us know Last updated on June 03, 2025