Known vulnerabilities in path-to-regexp

Vendor: pillarjs
Software CPE: cpe:2.3:a:pillarjs:path-to-regexp:*:*:*:*:*:*:*:*
Total vulnerabilities: 3
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting path-to-regexp path-to-regexp is affected by 3 known vulnerabilities: 3 low Critical High Medium Low

Vulnerabilities (3)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU126856 - Inefficient Regular Expression Complexity
CVE-2026-4867
CWE-1333 Low
No
No
0.1.10, 1.9.0, 3.3.0, 6.3.0, 8.0.0 22.04.2026 SB20260422207
SB20260422208
SB2026052938
and 5 more
#VU101895 - Inefficient Regular Expression Complexity
CVE-2024-52798
CWE-1333 Low
No
No
0.1.12 23.12.2024 SB2024122305
SB2024122309
SB2025011306
and 45 more
#VU98132 - Inefficient Regular Expression Complexity
CVE-2024-45296
CWE-1333 Low
No
No
0.1.10, 1.9.0, 3.3.0, 6.3.0, 8.0.0 08.10.2024 SB2024100822
SB2024100823
SB2024100826
and 87 more