CVE-2026-4923 identifies a Regular Expression Denial of Service (ReDoS) vulnerability, likely impacting libraries that generate regular expressions for path matching, such as path-to-regexp. This flaw occurs when specific combinations of multiple wildcards and parameters create a vulnerable regular expression. Rated Medium with a CVSS score of 5.9, this vulnerability has a network attack vector and high attack complexity, but can lead to a high impact on availability through denial of service. There is currently no evidence of active exploitation, nor are there any public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion is minimal, and affected users are advised to upgrade to version 8.4.0 or implement workarounds to validate regex output.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 8.4.0CPE matchmatch criteria | cpe:2.3:a:pillarjs:path-to-regexp:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.