Vulnerabilities/

path-to-regexp outputs backtracking regular expressions

Severity:
High

Description

A bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b.

Recommendation

Update the path-to-regexp package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
path-to-regexp
Anything's wrong? Let us know Last updated on January 24, 2025