Inefficient regular expression complexity in path-to-regexp - CVE-2026-4867

 

Inefficient regular expression complexity in path-to-regexp - CVE-2026-4867

Published: April 22, 2026


Vulnerability identifier: #VU126856
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-4867
CWE-ID: CWE-1333
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


Affected software

path-to-regexp
PowerVC
IBM Fusion HCI
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
IBM Business Automation Workflow
Rational Performance Tester
DevOps Test Performance
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Data Cataloging
IBM Maximo Scheduler Optimization
IBM QRadar Data Synchronization App

How to mitigate CVE-2026-4867

Install updates from vendor's website.

path-to-regexp - addressed in versions 0.1.10, 1.9.0, 3.3.0, 6.3.0, 8.0.0
IBM Fusion HCI - update to 2.13.0
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.20-sc2, 4.3.4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 4
DevOps Test Performance - update to 11.0.8
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.5
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
Data Cataloging - update to 2.5.3
IBM QRadar Data Synchronization App - update to 4.0.0
IBM Maximo Scheduler Optimization - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11

External References

Related Security Bulletins