Pillarjs maintains a narrowly scoped but highly embedded utility library for URL path parsing and manipulation that appears across a large number of web frameworks and routing middleware. The vendor's vulnerability footprint concentrates in its path_to_regexp product and recurs through weakness classes including regular-expression denial-of-service, prototype pollution, exception handling flaws, and resource-consumption conditions that are characteristic of parser libraries operating on untrusted input. Defenders should treat this as a supply-chain dependency requiring inventory and tracking, since remediation typically depends on downstream framework and application maintainers; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pillarjs over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4926HIGH Impact:
A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponent | Mar 26, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-8162HIGH [email protected] and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a Content-Disposition header whose fil | May 12, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-8161HIGH [email protected] and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a field name that collides with an inh | May 12, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-8159HIGH [email protected] and lower versions are vulnerable to denial of service via regular expression backtracking in the Content-Disposition filename parameter parser. A crafted multipar | May 12, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-4867HIGH Impact:
A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a | Mar 26, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-4923MEDIUM Impact:
When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability req | Mar 26, 2026 | 5.9 | 23 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pillarjs.
Media articles that mention a CVE ID that affects a product developed by Pillarjs — matched by CVE ID, not by vendor name.