CVE-2024-52798

path-to-regexp: Inefficient Regular Expression Complexity (CVE-2024-52798)

Description

A flaw was found in path-to-regexp. A path-to-regexp turns path strings into regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

npmpath-to-regexp

Metrics

7.7
Source: nvd-v4
54.8 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
high
no public PoC known
0.8 %
Low — model estimates < 1% exploitation likelihood.
Published
2024-12-05 22:45 UTC
CWE-1333

Weakness classes (CWE)

  • CWE-1333Base

    Inefficient Regular Expression Complexity

    The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

    cwe.mitre.org →

References & sources