npm vulnerability intelligence

path-to-regexp NPM Package
Vulnerability Check

Express style path to RegExp utility

High severity MIT v8.4.2
Vulnerability Analysis OSV Live

path-to-regexp

v8.4.2 · MIT · 181,960,777 dl/wk

Advisory Breakdown

Critical 0
High 4
Moderate 1
Low 0

Severity Rating

High severity

5 advisories

High severity

Weekly downloads

181,960,777

Total advisories

5

Latest version

8.4.2

License

MIT

Known advisories

OSV records for the npm ecosystem

5
GHSA-27v5-c462-wpq7 CVE-2026-4923 moderate

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards

Affected: >=8.0.0 <8.4.0 Fixed in: 8.4.0 Updated Mar 30, 2026
View source
GHSA-37ch-88jc-xwx2 CVE-2026-4867 high

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters

Affected: >=0 <0.1.13 Fixed in: 0.1.13 Updated Mar 31, 2026
View source
GHSA-9wv6-86v2-598j CVE-2024-45296 high

path-to-regexp outputs backtracking regular expressions

Affected: >=0.2.0 <1.9.0, >=0 <0.1.10, >=7.0.0 <8.0.0, >=2.0.0 <3.3.0, >=4.0.0 <6.3.0 Fixed in: 1.9.0, 0.1.10, 8.0.0, 3.3.0, 6.3.0 Updated Feb 4, 2026
View source
GHSA-j3q9-mxjg-w52f CVE-2026-4926 high

path-to-regexp vulnerable to Denial of Service via sequential optional groups

Affected: >=8.0.0 <8.4.0 Fixed in: 8.4.0 Updated Mar 30, 2026
View source
GHSA-rhx6-c78j-4q9w CVE-2024-52798 high

path-to-regexp contains a ReDoS

Affected: >=0 <0.1.12 Fixed in: 0.1.12 Updated Feb 4, 2026
View source

Checked Jun 14, 2026, 10:57 PM from npm and OSV.dev

Package metadata

From the npm registry

Package name
path-to-regexp
Ecosystem
npm
Latest version
8.4.2
License
MIT
Weekly downloads
181,960,777

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 6/14/2026, 10:57:10 PM