CVE-2024-52798
path-to-regexp: Inefficient Regular Expression Complexity (CVE-2024-52798)
highEPSS 0.8%
Description
A flaw was found in path-to-regexp. A path-to-regexp turns path strings into regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
npmpath-to-regexp
Metrics
Show all metrics
Severity
high
69.83
no public PoC known
7.7
Published
2024-12-05 22:45 UTC
CWE-1333
Weakness classes (CWE)
CWE-1333Base
Inefficient Regular Expression Complexity
The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.
cwe.mitre.org →
References & sources
- https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-rhx6-c78j-4q9wweb
- https://nvd.nist.gov/vuln/detail/CVE-2024-52798advisory
- https://github.com/pillarjs/path-to-regexp/commit/f01c26a013b1889f0c217c643964513acf17f6a4web
- https://blakeembrey.com/posts/2024-09-web-redosweb
- https://github.com/pillarjs/path-to-regexppackage
- https://security.netapp.com/advisory/ntap-20250124-0002web
- https://security.netapp.com/advisory/ntap-20250124-0002/