Path Equivalence Affecting rou3 package, versions <0.7.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ROU3-14459107
  • published17 Dec 2025
  • disclosed16 Dec 2025
  • creditGoksan

Introduced: 16 Dec 2025

CVE NOT AVAILABLE CWE-41  (opens in a new tab)

How to fix?

Upgrade rou3 to version 0.7.0 or higher.

Overview

rou3 is a Lightweight and fast router for JavaScript.

Affected versions of this package are vulnerable to Path Equivalence due to insufficient preservation of empty segments. An attacker can bypass access restrictions and rate limits by sending requests with multiple slashes in the URL path, which are normalized and treated as identical routes.

References

CVSS Base Scores

version 4.0
version 3.1