8.3.0
13 years ago
1 months ago
Known vulnerabilities in the path-to-regexp package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version | 
|---|---|
| 
 Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) when including multiple regular expression parameters in a single segment, which will produce the regular expression  Note:
While the 8.0.0 release has completely eliminated the vulnerable functionality, prior versions that have received the patch to mitigate backtracking may still be vulnerable if custom regular expressions are used. So it is strongly recommended for regular expression input to be controlled to avoid malicious performance degradation in those versions. This behavior is enforced as of version 7.1.0 via the  How to fix Regular Expression Denial of Service (ReDoS)? Upgrade  | <0.1.10>=0.2.0 <1.9.0>=2.0.0 <3.3.0>=4.0.0 <6.3.0>=7.0.0 <8.0.0 |