Inefficient regular expression complexity in path-to-regexp - CVE-2026-4867
Published: April 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
PowerVC
IBM Fusion HCI
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
IBM Business Automation Workflow
Rational Performance Tester
DevOps Test Performance
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Data Cataloging
IBM Maximo Scheduler Optimization
IBM QRadar Data Synchronization App
How to mitigate CVE-2026-4867
IBM Fusion HCI - update to 2.13.0
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.20-sc2, 4.3.4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 4
DevOps Test Performance - update to 11.0.8
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.5
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
Data Cataloging - update to 2.5.3
IBM QRadar Data Synchronization App - update to 4.0.0
IBM Maximo Scheduler Optimization - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
External References
Related Security Bulletins
- Inefficient regular expression complexity in path-to-regexp
- IBM DevOps Test Performance update for path-to-regexp
- Platform Navigator and Automation Assets in IBM Cloud Pak for Integration update for path-to-regexp
- IBM Watson Discovery Cartridge update for path-to-regexp-0.1.12.tgz
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- IBM Maximo Scheduler Optimization update for path-to-regexp
- IBM Fusion, IBM Fusion HCI, and IBM Fusion Data Cataloging update for path-to-regexp
- IBM PowerVC update for path-to-regexp
- Multiple vulnerabilities in IBM QRadar Data Synchronization App
- Multiple vulnerabilities in IBM Business Automation Workflow