CVE-2024-45296
pkg:npm/path-to-regexp@6.2.2
Why this label
- evidence_sufficient 0.93 ≥ 0.50
- → SUPPORTED: target_affected 0.97 ≥ 0.90, reproduced_on_target 0.98 ≥ 0.80, no claim disputed ≥ 0.50
Generated 2026-10-04 21:12 UTC · investigators anthropic/claude-sonnet-5.5 · judge typesafe-ai/jev
Claims
| Claim | Verdict | Technically supported | Credibly disputed |
|---|---|---|---|
The affected product is path-to-regexp. product · asserted by CVE description | ✓ supported | 0.98 | 0.03 |
GHSA identifies affected versions as < 0.1.10, >= 0.2.0 and < 1.9.0, >= 2.0.0 and < 3.3.0, >= 4.0.0 and < 6.3.0, and >= 7.0.0 and < 8.0.0. versions · asserted by GHSA | ✓ supported | 0.83 | 0.11 |
OSV identifies affected versions as < 0.1.10, >= 0.2.0 and < 1.9.0, >= 2.0.0 and < 3.3.0, >= 4.0.0 and < 6.3.0, and >= 7.0.0 and < 8.0.0. versions · asserted by OSV | ✓ supported | 0.91 | 0.06 |
No privileges are required to exploit the vulnerability. auth · asserted by NVD | · unverified | 0.52 | 0.04 |
The attack vector is network-based. vector · asserted by NVD | · unverified | 0.16 | 0.06 |
The problematic regular expression is generated when two parameters occur within one path segment and are separated by a character other than a period. vector · asserted by CVE description | ✓ supported | 0.94 | 0.03 |
Exploitation can cause poor regular-expression matching performance. impact · asserted by CVE description | ✓ supported | 0.98 | 0.03 |
Poor matching performance can block the JavaScript event loop. impact · asserted by CVE description | ✓ supported | 0.96 | 0.03 |
path-to-regexp@6.2.2 is affected by CVE-2024-45296 target · asserted by the scan or report under review | ✓ supported | 0.97 | 0.06 |
Technical evidence
- Vulnerable code
- path-to-regexp 6.2.2 (src/index.ts, tokensToRegexp / tokenToRegexp): the default parameter pattern is [^\/#\?]+? with no exclusion of the preceding separator. For '/:a-:b-:c' this yields adjacent lazy groups separated by '-', so a non-matching input with many '-' causes about cubic backtracking. 6.3.0 adds a (?!-) lookahead.
- PoC
- Compile '/:a-:b-:c', then time re.test('/' + '-'*n + '/x'), which cannot match and forces backtracking. Print the regex source and elapsed ms per n. v8.0.0 has no pathToRegexp export, so a separate script used match('/:a-:b-:c')(s) with the same input.
Script
const m=require(process.cwd()+'/node_modules/path-to-regexp');
const path='/:a-:b-:c';
let re;
if(typeof m==='function') re=m(path,[]);
else { const r=m.pathToRegexp(path); re=r.regexp||r; }
console.log(re.source);
for(const n of [1000,2000]){
const s='/'+'-'.repeat(n)+'/x';
const t=process.hrtime.bigint();re.test(s);
console.log(n,Number(process.hrtime.bigint()-t)/1e6,'ms');
}| Version | Role | Result |
|---|---|---|
| 6.2.2 | target | reproduced n=1000: 464ms; n=2000: 2400ms; n=4000: 18397ms (cubic growth). |
| 6.2.1 | positive control | reproduced Same regex as 6.2.2. n=1000: 290ms; n=2000: 2319ms. |
| 0.1.9 | positive control | reproduced n=1000: 176ms; n=2000: 1388ms. |
| 6.3.0 | fixed | not reproduced Regex uses (?!-) lookaheads. n=1000: 0.09ms; n=2000: 0.01ms. |
| 8.0.0 | fixed | not reproduced match('/:a-:b-:c') on the same input: n=20000 took 0.08ms. |
| 0.1.10 | other | reproduced Still slow for '/:a-:b-:c': n=1000 180ms, n=2000 1420ms. Its regex still has ([^/]+?). |
| 0.1.12 | other | not reproduced Regex has (?!\/|-) lookaheads. n=2000: 0.01ms. |
Only the '/:a-:b-:c' pattern was tested, with the n=1000 and n=2000 sizes (n=4000 on 6.2.2 only). The 1.x, 2.x, 3.x and 7.x lines were not installed. Against the fix commit 29b96b4, 0.1.10 still produced an unprotected regex for this pattern, but 0.1.12 was protected. This may mean the stated 0.1.10 fixed boundary is incomplete for this pattern. No network service was run; c4 and c5 are deployment and CVSS properties.
Discourse evidence
The maintainer advisory (blakeembrey) says versions >=4.0.0 <6.3.0 are affected and fixed in 6.3.0, which puts 6.2.2 in range. It describes the two-parameters-per-segment regex, the event-loop blocking, and a CVSS vector of AV:N/PR:N. The only dispute found is a user (issue #328) saying NVD still flags the fixed versions. The maintainer replied that the checker needs fixing. No source disputes the claim about 6.2.2.
A bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (`.`). For example, `/:a-:b`.
Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and can lead to a DoS.
In local benchmarks, exploiting the unsafe regex will result in performance that is over 1000x worse than the safe regex.
Affected versions: >=4.0.0, <6.3.0 ... Patched versions: 6.3.0
These versions add backtrack protection when a custom regex pattern is not provided: ... 6.3.0
>=4.0.0, <6.3.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Privileges required None
No, the fixes were already released. This would need to be fixed in the vulnerability checker since I don't see how releasing another version would fix this now.
some vulnerability checkers (nvd.nist.gov) are still considering as a broken version.
Unresolved
- No source explicitly names 6.2.2; it is affected only via the range >=4.0.0 <6.3.0 (fixed in 6.3.0).
- NVD lists no machine-readable ranges, so NVD's stance on 6.2.2 was not confirmed.
- The NVD page was not fetched, so NVD's own CVSS vector wording (c4/c5) is unverified. The quotes used come from the GitHub advisory CVSS.
- Scanner vendor notes (e.g., NetApp advisory) were not reviewed.
Jev scores
| Bug exists in some version | 0.98 |
| Target version affected | 0.97 |
| Evidence sufficient | 0.93 |
| Reproduced on target | 0.98 |
| Patch addresses the issue | 0.93 |
| Credible dispute exists | 0.11 |
| Impact matches description | 0.95 |
| Positive control reproduced | 0.98 |
| Authority of dispute (0 none – 3 maintainer) | 0.99 |
Official record
path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.
| Source | Affected ranges | Covers target? |
|---|---|---|
| nvd | — | — |
| ghsa | < 0.1.10 || >= 0.2.0 < 1.9.0 || >= 2.0.0 < 3.3.0 || >= 7.0.0 < 8.0.0 || >= 4.0.0 < 6.3.0 | yes |
| osv | >=0.2.0 <1.9.0 || <0.1.10 || >=7.0.0 <8.0.0 || >=2.0.0 <3.3.0 || >=4.0.0 <6.3.0 | yes |
OSV reports for this exact version: GHSA-9wv6-86v2-598j, CVE-2024-45296, CVE-2026-4867, GHSA-37ch-88jc-xwx2 · CVSS 7.5 HIGH · CWE-1333
Evidence quality
- ✓Fix commit or release identified
- ✓Vulnerable code path identified
- ✓Positive control reproduced
- ✓Target version tested
- ✓Maintainer or vendor statement found
- ✓Sources agree on whether the target is in range
Run history
- 2026-10-04 21:09 · succeeded · SUPPORTED
- 2026-10-04 19:58 · succeeded · SUPPORTED
- 2026-10-04 19:56 · succeeded · SUPPORTED
- 2026-10-04 19:53 · failed
- 2026-10-04 19:52 · failed
- 2026-10-04 19:49 · failed