A Denial-of-Service Vector in Every Route Match
A medium-severity vulnerability in path-to-regexp 0.1.12 exposes any service using this package to CPU exhaustion through maliciously crafted URL parameters. The issue—tracked as CVE-2026-4867—stems from catastrophic backtracking in the regular expression engine when parsing malformed input, allowing remote attackers to hang the event loop with a single HTTP request.
This is particularly dangerous because path-to-regexp sits at the core of Express.js routing and numerous Node.js web frameworks. Every route definition, every parameterized URL, and every path match flows through this parsing logic.
Affected Versions
| Affected | <= 0.1.12 |
| Fixed in | 0.1.13 |
| Ecosystem | npm |
| CVE / GHSA | CVE-2026-4867 / not assigned |
| CWE | unknown |
The Vulnerability Explained
The path-to-regexp package converts route strings like /users/:id into regular expressions for matching incoming URLs. The vulnerability lies in how certain malformed parameter patterns interact with the regex construction.
Consider how the package processes parameterized routes. When a route contains repeating patterns or nested groups, the regex engine can enter a state where it attempts exponentially many matching paths—what security researchers call "catastrophic backtracking."
Before the fix, version 0.1.12 carried this vulnerable pattern:
{
"version": "0.1.12",
"resolved": "https://registry.npmjs.org/path-to-regexp/-/path-to-regexp-0.1.12.tgz"
}
An attacker exploiting this could send a URL with carefully constructed parameters containing nested quantifiers—for example, repeated asterisks or plus signs in positions that force the regex engine to explore millions of match permutations. A request like:
GET /api//////////... (hundreds of consecutive slashes followed by malformed parameter sequences)
would cause the Node.js process to spike to 100% CPU and hang indefinitely. The event loop blockage persists until the process is terminated, affecting all concurrent connections.
The real-world impact is severe for any service using Express.js or direct path-to-regexp calls for routing. A single HTTP request can render the entire application unresponsive.
The Fix
The resolution in version 0.1.13 hardens the regex construction to eliminate the backtracking vulnerability while preserving matching semantics:
{
"version": "0.1.13",
"resolved": "https://registry.npmjs.org/path-to-regexp/-/path-to-regexp-0.1.13.tgz"
}
The 0.1.13 release restructures internal regex patterns to use possessive quantifiers and atomic groups where possible, preventing the regex engine from revisiting previously matched characters. This change ensures that even pathologically malformed input fails fast rather than consuming unbounded CPU cycles.
The maintainers achieved this without altering the public API—pathToRegexp(), match(), parse(), and compile() all behave identically for valid input. Only the failure mode for malicious input changed: where 0.1.12 would hang, 0.1.13 returns quickly with no match.
Key Takeaways
- Regex engines are a trust boundary: Any package parsing untrusted strings through regular expressions requires scrutiny for ReDoS patterns, even in mature, widely-used dependencies.
- Patch versions matter for security: The 0.1.12 → 0.1.13 increment represents a critical security boundary, not merely maintenance. Dependency update policies should treat patch bumps as potentially security-relevant.
- Framework internals propagate risk: Because
path-to-regexpsits beneath Express routing, applications inherit this vulnerability even without direct package imports. Audit transitive dependencies, not just direct ones. - Catastrophic backtracking has no timeout: Unlike network timeouts or query limits, regex engine backtracking blocks the entire process. There's no graceful degradation—only hard termination.
How Orbis AppSec Detected This
Source: URL path parameters passed to Express.js routing middleware
Sink: pathToRegexp() function compiling route patterns into executable regular expressions
Missing control: No input length validation or regex timeout mechanism before pattern compilation
CWE: unknown
Fix: Upgraded path-to-regexp from 0.1.12 to 0.1.13, replacing vulnerable regex construction with hardened patterns that prevent exponential backtracking
Orbis AppSec detected this vulnerability automatically. Try Orbis AppSec on your repositories to find and fix issues like this.
Conclusion
CVE-2026-4867 demonstrates that even single-patch-version increments in foundational packages carry security significance. The path-to-regexp vulnerability exposed every Express application to trivial DoS attacks through malformed URL parameters. Upgrading to 0.1.13 closes this vector without code changes—making this one of the highest-impact, lowest-effort security updates available to Node.js developers.