Two disclosed vulnerabilities, CVE-2026-4923 and CVE-2026-4926, affect the widely used path-to-regexp library and can cause regular expression denial of service (ReDoS) in Node.js applications. In both cases, crafted input can trigger catastrophic backtracking in route-matching logic, consuming CPU and memory and blocking the single-threaded Node.js event loop so applications stop processing HTTP requests, timers, and asynchronous callbacks.
The flaws primarily impact availability rather than confidentiality or integrity. CVE-2026-4923 was rated CVSS 5.9 and depends on specific developer-defined routing configurations, with simple routing patterns reportedly unaffected, while CVE-2026-4926 was rated CVSS 7.5 with low attack complexity and no required privileges or user interaction. Although reported exploitation likelihood remains low, the library’s broad adoption across the Node.js ecosystem increases exposure, particularly for applications that allow externally influenced route definitions.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Two denial-of-service vulnerabilities affecting path-to-regexp were publicly documented. Both issues can cause Node.js applications to become unresponsive through catastrophic regular-expression backtracking that blocks the single-threaded event loop.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.