Known vulnerabilities in path-to-regexp
Vendor:
pillarjs
Software:
path-to-regexp
Software CPE:
cpe:2.3:a:pillarjs:path-to-regexp:*:*:*:*:*:*:*:*
Website:
https://pillarjs.github.io/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
8.4.2
8.4.1
8.4.0
0.1.13
8.3.0
0.1.12
8.2.0
8.1.0
8.0.0
7.2.0
7.1.0
7.0.0
6.3.0
6.2.2
6.2.1
6.2.0
6.1.0
6.0.0
5.0.0
4.0.5
4.0.4
4.0.3
4.0.2
4.0.1
4.0.0
3.3.0
3.2.0
3.1.0
3.0.0
2.4.0
2.3.0
2.2.1
2.2.0
2.1.0
2.0.0
1.9.0
1.8.0
1.7.0
1.6.0
1.5.3
1.5.2
1.5.1
1.5.0
1.4.0
1.3.0
1.2.1
1.2.0
1.1.1
1.1.0
1.0.3
1.0.2
1.0.1
1.0.0
0.2.5
0.2.4
0.2.3
0.2.2
0.2.1
0.2.0
0.1.11
0.1.10
0.1.9
0.1.8
0.1.7
0.1.6
0.1.5
0.1.4
0.1.3
0.1.2
0.1.1
0.1.0
0.0.2
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU126856 - Inefficient Regular Expression Complexity CVE-2026-4867 |
CWE-1333 | Low | 0.1.10, 1.9.0, 3.3.0, 6.3.0, 8.0.0 | 22.04.2026 |
SB20260422207 SB20260422208 SB2026052938 and 5 more |
||
| #VU101895 - Inefficient Regular Expression Complexity CVE-2024-52798 |
CWE-1333 | Low | 0.1.12 | 23.12.2024 |
SB2024122305 SB2024122309 SB2025011306 and 45 more |
||
| #VU98132 - Inefficient Regular Expression Complexity CVE-2024-45296 |
CWE-1333 | Low | 0.1.10, 1.9.0, 3.3.0, 6.3.0, 8.0.0 | 08.10.2024 |
SB2024100822 SB2024100823 SB2024100826 and 87 more |