/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-52798

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-52798

Severity

Unknown

Summary

path-to-regexp Unpatched path-to-regexp ReDoS in 0.1.x

Description

path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path-to-regexp. Upgrade to 0.1.12. This vulnerability exists because of an incomplete fix for CVE-2024-45296.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing