PT-2024-35449 · Unknown · Path-To-Regexp

·

CVE-2024-52798

·

Published

2024-12-05

·

Updated

2026-07-14

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions path-to-regexp versions 0.1.x through 0.1.11
Description The issue concerns a performance vulnerability in path-to-regexp, where certain inputs can generate regular expressions vulnerable to backtracking, leading to poor performance. This vulnerability exists due to an incomplete fix.
Recommendations Upgrade to version 0.1.12. As a temporary workaround, consider avoiding the use of two parameters within a single path segment when the separator is not . (e.g., no /:a-:b). Alternatively, define the regex used for both parameters and ensure they do not overlap to allow backtracking.

Exploit

Fix

Resource Exhaustion

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-54017
AZL-54020
AZL-54036
BDU:2026-01468
CVE-2024-52798
GHSA-RHX6-C78J-4Q9W

Affected Products

Path-To-Regexp