PatchSiren

path-to-regexp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH path-to-regexp CVE published 2026-03-26

CVE-2026-4926

A vulnerability in the path-to-regexp library can cause a denial of service when a regular expression with multiple sequential optional groups is generated. This issue was fixed in version 8.4.0. Users should update to the latest version and limit the number of sequential optional groups in route patterns. The vulnerability is triggered by a bad regular expression generated from multiple sequential option [truncated]