Skip to content

chore(deps): update dependency path-to-regexp to v8.4.0 [security]#8361

Open
backstage-goalie[bot] wants to merge 1 commit intomainfrom
renovate/npm-path-to-regexp-vulnerability
Open

chore(deps): update dependency path-to-regexp to v8.4.0 [security]#8361
backstage-goalie[bot] wants to merge 1 commit intomainfrom
renovate/npm-path-to-regexp-vulnerability

Conversation

@backstage-goalie
Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
path-to-regexp 8.3.08.4.0 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards

CVE-2026-4923 / GHSA-27v5-c462-wpq7

More information

Details

Impact

When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path.

Unsafe examples:

/*foo-*bar-:baz
/*a-:b-*c-:d
/x/*a-:b/*c/y

Safe examples:

/*foo-:bar
/*foo-:bar-*baz
Patches

Upgrade to version 8.4.0.

Workarounds

If developers are using multiple wildcard parameters, they can check the regex output with a tool such as https://makenowjust-labs.github.io/recheck/playground/ to confirm whether a path is vulnerable.

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


path-to-regexp vulnerable to Denial of Service via sequential optional groups

CVE-2026-4926 / GHSA-j3q9-mxjg-w52f

More information

Details

Impact

A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as {a}{b}{c}:z. The generated regex grows exponentially with the number of groups, causing denial of service.

Patches

Fixed in version 8.4.0.

Workarounds

Limit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

pillarjs/path-to-regexp (path-to-regexp)

v8.4.0: 8.4.0

Compare Source

Important

Fixed

  • Restricts wildcard backtracking when using more than 1 in a path (#​421)

Changed

  • Dedupes regex prefixes (#​422)
    • This will result in shorter regular expressions for some cases using optional groups
  • Rejects large optional route combinations (#​424)
    • When using groups such as /users{/delete} it will restrict the number of generated combinations to < 256, equivalent to 8 top-level optional groups and unlikely to occur in a real world application, but avoids exploding the regex size for applications that accept user created routes

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@backstage-goalie backstage-goalie bot added the dependencies Pull requests that update a dependency file label Mar 28, 2026
@backstage-goalie backstage-goalie bot requested a review from Parsifal-M March 28, 2026 00:23
@backstage-goalie backstage-goalie bot force-pushed the renovate/npm-path-to-regexp-vulnerability branch 2 times, most recently from 00ce507 to 1eb175b Compare March 28, 2026 21:15
@backstage-goalie backstage-goalie bot changed the title chore(deps): update dependency path-to-regexp to v8.4.0 [security] chore(deps): update dependency path-to-regexp to v8.4.0 [security] - autoclosed Mar 29, 2026
@backstage-goalie backstage-goalie bot closed this Mar 29, 2026
@backstage-goalie backstage-goalie bot deleted the renovate/npm-path-to-regexp-vulnerability branch March 29, 2026 09:18
@backstage-goalie backstage-goalie bot changed the title chore(deps): update dependency path-to-regexp to v8.4.0 [security] - autoclosed chore(deps): update dependency path-to-regexp to v8.4.0 [security] Mar 29, 2026
@backstage-goalie backstage-goalie bot reopened this Mar 29, 2026
@backstage-goalie backstage-goalie bot force-pushed the renovate/npm-path-to-regexp-vulnerability branch 8 times, most recently from 97d5e43 to 3f8208d Compare March 31, 2026 06:35
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security workspace/apiiro workspace/mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant