CVE Database
/

CVE-2024-52798

Back to search

CVE-2024-52798

Published: Dec 5, 2024

Modified: Jan 24, 2025

PUBLISHED

Description

path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path-to-regexp. Upgrade to 0.1.12. This vulnerability exists because of an incomplete fix for CVE-2024-45296.

VendorProductVersions

pillarjs

path-to-regexp

affected
< 0.1.12

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now