PT-2026-28675 · Unknown · Path-To-Regexp

·

CVE-2026-4926

·

Publicado

2026-01-01

·

Atualizado

2026-07-09

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions path-to-regexp versions prior to 8.4.0
Description A flawed regular expression is created when multiple sequential optional groups (using curly brace syntax) are present, such as {a}{b}{c}:z. The resulting regular expression expands exponentially with the number of groups, potentially leading to a denial of service. Avoid passing user-controlled input as route patterns.
Recommendations Versions prior to 8.4.0 should be updated to version 8.4.0 or later. Limit the number of sequential optional groups in route patterns.

Exploit

Correção

DoS

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CLEANSTART-2026-AD27625
CLEANSTART-2026-BE61221
CLEANSTART-2026-IS05941
CLEANSTART-2026-KS09647
CLEANSTART-2026-TW25027
CLEANSTART-2026-TZ34913
CLEANSTART-2026-XR95601
CVE-2026-4926
GHSA-J3Q9-MXJG-W52F
RHSA-2026:24761
RHSA-2026:24762

Produtos afetados

Path-To-Regexp