PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-4926 path-to-regexp CVE debrief

A vulnerability in the path-to-regexp library can cause a denial of service when a regular expression with multiple sequential optional groups is generated. This issue was fixed in version 8.4.0. Users should update to the latest version and limit the number of sequential optional groups in route patterns. The vulnerability is triggered by a bad regular expression generated from multiple sequential optional groups (curly brace syntax), such as {a}{b}{c}:z, causing exponential growth and denial of service. Defenders should assess exposure and prioritize updating to version 8.4.0 or later.

Vendor
path-to-regexp
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-26
Original CVE updated
2026-09-09
Advisory published
2026-03-26
Advisory updated
2026-09-09

Who should care

Defenders and developers using the path-to-regexp library should assess exposure and prioritize updating to version 8.4.0 or later. They should review route patterns and limit sequential optional groups to prevent denial of service attacks. Security teams and vulnerability management teams should track exceptions and retest remediated assets.

Why it matters

CVE-2026-4926 vulnerability in path-to-regexp library can cause denial of service. Defenders should prioritize updating and review route patterns.

  • Denial of service attacks may be possible due to the vulnerability
  • Defenders should verify route patterns and limit sequential optional groups
  • Updating to version 8.4.0 or later is recommended

Technical summary

The path-to-regexp library generates a bad regular expression when multiple sequential optional groups are used, causing a denial of service. The issue is fixed in version 8.4.0. Users should update and limit sequential optional groups in route patterns to prevent exploitation. The vulnerability is caused by exponential growth of the generated regex, which can be triggered by user-controlled input as route patterns. Defenders should prioritize updating to version 8.4.0 or later and review route patterns to limit sequential optional groups.

Defensive priority

Defenders should prioritize updating to version 8.4.0 or later and review route patterns to limit sequential optional groups.

Recommended defensive actions

  • Update to version 8.4.0 or later
  • Review and limit sequential optional groups in route patterns
  • Monitor for potential denial of service attacks
  • Verify affected product deployments exist in managed environments
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD vulnerability detail page provide information on the vulnerability and its fix. Red Hat errata RHSA-2026:10153, RHSA-2026:10172, RHSA-2026:10175, and others provide additional information on affected systems and patches. The vulnerability has been publicly disclosed and defenders should verify route patterns and limit sequential optional groups. Evidence limits suggest that defenders review compensating controls and monitor for potential denial of service attacks.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-4926 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-4926

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-4926 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4926

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cna.openjsf.org/security-advisories.html

    ce714d77-add3-4f53-aff5-83d477b104bb - Third Party Advisory

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:10153

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:10172

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:10175

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:13545

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:13826

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:17789

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:19409

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.