Red Hat issued security updates for OpenShift and related products to remediate CVE-2024-45296 in path-to-regexp and CVE-2024-43796 in Express.js. The path-to-regexp flaw permits regular-expression denial of service when a crafted route pattern places two parameters in one path segment separated by a non-period character, potentially blocking Node.js's single-threaded event loop. Express versions before 4.20.0 can improperly handle untrusted input passed to response.redirect(), potentially enabling execution of untrusted code even when the input has been sanitized.
Affected updates include OpenShift Data Foundation 4.14.13, 4.15.9, and 4.17.0 container images, as well as OpenShift Container Platform 4.17 releases and other Red Hat offerings such as OpenShift Service Mesh, Serverless, OpenShift AI, Dev Spaces, Network Observability, and the Red Hat build of Apache Camel. The advisories also address additional bundled-component flaws, including prototype pollution, unsafe redirects, DOM clobbering, resource exhaustion, and potential code execution. Administrators should apply the applicable Red Hat errata and upgrade path-to-regexp to 0.1.10 on the 0.1 branch or 8.0.0 on other branches, and Express to 4.20.0 or later.

See real exploitation activity before you spend the cycle.
18 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2025:1051 for OpenShift Service Mesh Containers 2.5.8 on RHEL 8. The update remediates CVE-2024-52798 in path-to-regexp, CVE-2024-55565 in nanoid, and CVE-2024-45338 in golang.org/x/net/html across affected architectures.
Red Hat issued Important-rated RHSA-2025:0875 and released OpenShift Container Platform 4.17.15, fixing CVE-2024-43796 and CVE-2024-45296 along with other third-party component vulnerabilities.
RHSA-2025:0164 supplied updated OpenShift Data Foundation 4.15.9 container images for RHEL 9 that fix CVE-2024-43796 and the path-to-regexp ReDoS vulnerability CVE-2024-45296.
Red Hat issued RHSA-2024:11023 for HawtIO 4.1.0 in Red Hat build of Apache Camel 4, addressing CVE-2024-43796 and CVE-2024-45296 among nine vulnerabilities.
Red Hat issued RHSA-2024:8676 with updated OpenShift Data Foundation 4.17.0 images for RHEL 9, remediating CVE-2024-43796 in Express redirects and CVE-2024-45296 in path-to-regexp.
Red Hat issued RHSA-2024:7922 for OpenShift Container Platform 4.17.1, including a fix for CVE-2024-45296, a path-to-regexp regular-expression backtracking denial-of-service flaw.
Red Hat Bugzilla record 2324550 tracks CVE-2024-21538, a regular-expression denial-of-service vulnerability in cross-spawn.
Red Hat identified RHSA-2025:0079 for CVE-2024-43796 in RHODF 4.17, RHSA-2025:0082 for both vulnerabilities in RHODF 4.16, and RHSA-2025:0664 for CVE-2024-45296 in RHOSS 1.35.
RHSA-2024:10906 addressed CVE-2024-43796 and CVE-2024-45296 in Red Hat Migration Toolkit for Containers 1.8.
Red Hat addressed CVE-2024-45296 in Red Hat Ansible Automation Platform 2.4 for RHEL 8 and RHEL 9 through RHSA-2024:10762.
Red Hat addressed CVE-2024-45296 in Red Hat OpenShift Dev Spaces 3 Containers through RHSA-2024:10236.
Red Hat issued RHSA-2024:8023 to address CVE-2024-43796 in RHOSS-1.34-RHEL-8.
RHSA-2024:8014 addressed CVE-2024-43796 and CVE-2024-45296 in Network Observability 1.7.0 for RHEL 9.
Red Hat addressed CVE-2024-45296 in OpenShift Container Platform 4.16 through RHSA-2024:7599.
Red Hat issued RHSA-2024:7726 to address CVE-2024-43796 and CVE-2024-45296 in OpenShift Service Mesh 2.6 for RHEL 8 and RHEL 9.
Express versions earlier than 4.20.0 can execute untrusted code when untrusted input is passed to response.redirect(), including in some cases where the input was sanitized; Express 4.20.0 patches CVE-2024-43796.
The path-to-regexp flaw occurs when two parameters in one path segment are separated by a non-period character, enabling an inefficient regular expression to block JavaScript's main event loop. Users of the 0.1 line were directed to upgrade to 0.1.10, while other users were directed to upgrade to 8.0.0.
Red Hat issued RHSA-2025:0323 with refreshed OpenShift Data Foundation 4.14.13 images for RHEL 9, remediating CVE-2024-43796 and CVE-2024-45296.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
15 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.