CVE-2026-4926 is a high-severity denial-of-service vulnerability (CWE-1333, CWE-400) where inefficient regular expression generation, specifically with multiple sequential optional groups, leads to exponential regex growth and system unavailability. While the specific affected product is not detailed, this flaw carries a CVSS score of 7.5 (High) due to its network-based attack vector and low complexity, resulting in a high impact on availability. Currently, there is no evidence of active exploitation, nor is public exploit code available; however, the vulnerability has received some limited community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 8.4.0CPE matchmatch criteria | cpe:2.3:a:pillarjs:path-to-regexp:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.