PatchSiren cyber security CVE debrief
CVE-2026-4926 path-to-regexp CVE debrief
A vulnerability in the path-to-regexp library can cause a denial of service when a regular expression with multiple sequential optional groups is generated. This issue was fixed in version 8.4.0. Users should update to the latest version and limit the number of sequential optional groups in route patterns. The vulnerability is triggered by a bad regular expression generated from multiple sequential optional groups (curly brace syntax), such as {a}{b}{c}:z, causing exponential growth and denial of service. Defenders should assess exposure and prioritize updating to version 8.4.0 or later.
- Vendor
- path-to-regexp
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-26
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-03-26
- Advisory updated
- 2026-09-09
Who should care
Defenders and developers using the path-to-regexp library should assess exposure and prioritize updating to version 8.4.0 or later. They should review route patterns and limit sequential optional groups to prevent denial of service attacks. Security teams and vulnerability management teams should track exceptions and retest remediated assets.
Why it matters
CVE-2026-4926 vulnerability in path-to-regexp library can cause denial of service. Defenders should prioritize updating and review route patterns.
- Denial of service attacks may be possible due to the vulnerability
- Defenders should verify route patterns and limit sequential optional groups
- Updating to version 8.4.0 or later is recommended
Technical summary
The path-to-regexp library generates a bad regular expression when multiple sequential optional groups are used, causing a denial of service. The issue is fixed in version 8.4.0. Users should update and limit sequential optional groups in route patterns to prevent exploitation. The vulnerability is caused by exponential growth of the generated regex, which can be triggered by user-controlled input as route patterns. Defenders should prioritize updating to version 8.4.0 or later and review route patterns to limit sequential optional groups.
Defensive priority
Defenders should prioritize updating to version 8.4.0 or later and review route patterns to limit sequential optional groups.
Recommended defensive actions
- Update to version 8.4.0 or later
- Review and limit sequential optional groups in route patterns
- Monitor for potential denial of service attacks
- Verify affected product deployments exist in managed environments
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and NVD vulnerability detail page provide information on the vulnerability and its fix. Red Hat errata RHSA-2026:10153, RHSA-2026:10172, RHSA-2026:10175, and others provide additional information on affected systems and patches. The vulnerability has been publicly disclosed and defenders should verify route patterns and limit sequential optional groups. Evidence limits suggest that defenders review compensating controls and monitor for potential denial of service attacks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-4926 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-4926
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-4926 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4926
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cna.openjsf.org/security-advisories.html
ce714d77-add3-4f53-aff5-83d477b104bb - Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:10153
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:10172
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:10175
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:13545
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:13826
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:17789
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:19409
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.