Skip to content

chore(deps): update dependency path-to-regexp to v8.4.0 [security]#1022

Merged
renovate[bot] merged 1 commit intomasterfrom
renovate/npm-path-to-regexp-vulnerability
Mar 28, 2026
Merged

chore(deps): update dependency path-to-regexp to v8.4.0 [security]#1022
renovate[bot] merged 1 commit intomasterfrom
renovate/npm-path-to-regexp-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Mar 28, 2026

This PR contains the following updates:

Package Change Age Confidence
path-to-regexp 8.3.08.4.0 age confidence

GitHub Vulnerability Alerts

CVE-2026-4923

Impact

When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path.

Unsafe examples:

/*foo-*bar-:baz
/*a-:b-*c-:d
/x/*a-:b/*c/y

Safe examples:

/*foo-:bar
/*foo-:bar-*baz

Patches

Upgrade to version 8.4.0.

Workarounds

If developers are using multiple wildcard parameters, they can check the regex output with a tool such as https://makenowjust-labs.github.io/recheck/playground/ to confirm whether a path is vulnerable.

CVE-2026-4926

Impact

A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as {a}{b}{c}:z. The generated regex grows exponentially with the number of groups, causing denial of service.

Patches

Fixed in version 8.4.0.

Workarounds

Limit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.


Release Notes

pillarjs/path-to-regexp (path-to-regexp)

v8.4.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot enabled auto-merge (squash) March 28, 2026 20:54
@renovate renovate bot merged commit 8d099e0 into master Mar 28, 2026
2 checks passed
@renovate renovate bot deleted the renovate/npm-path-to-regexp-vulnerability branch March 28, 2026 20:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants