The security policy can be found at https://github.com/expressjs/.github/blob/master/SECURITY.md
Security: pillarjs/path-to-regexp
Security
SECURITY.md
-
path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcardsGHSA-27v5-c462-wpq7 published
Mar 26, 2026 by UlisesGasconModerate -
path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parametersGHSA-37ch-88jc-xwx2 published
Mar 26, 2026 by UlisesGasconHigh -
path-to-regexp vulnerable to Denial of Service via sequential optional groupsGHSA-j3q9-mxjg-w52f published
Mar 26, 2026 by UlisesGasconHigh -
Unpatched `path-to-regexp` ReDoS in 0.1.xGHSA-rhx6-c78j-4q9w published
Dec 5, 2024 by blakeembreyHigh -
Backtracking regular expressions cause ReDoSGHSA-9wv6-86v2-598j published
Sep 9, 2024 by blakeembreyHigh
Learn more about advisories related to pillarjs/path-to-regexp in the GitHub Advisory Database