find-my-way has a ReDoS vulnerability in multiparametric routes
Package
Affected versions
>= 9.0.0, < 9.0.1
>= 5.5.0, < 8.2.2
Patched versions
9.0.1
8.2.2
Description
Published to the GitHub Advisory Database
Sep 18, 2024
Reviewed
Sep 18, 2024
Published by the National Vulnerability Database
Sep 18, 2024
Last updated
Oct 7, 2024
Impact
A bad regular expression is generated any time you have two parameters within a single segment, when adding a
-
at the end, like/:a-:b-
.Patches
Update to find-my-way v8.2.2 or v9.0.1. or subsequent versions.
Workarounds
No known workarounds.
References
path-to-regexp
vulnerabilityReferences