> USN-8290-1: Path-to-Regexp vulnerability
[DATE: 21/05/2026 11:27]
[LANGUAGE: EN]
It was discovered that Path-to-Regexp incorrectly handled route patterns
containing multiple named parameters separated by non-delimiter characters
such as hyphens. An attacker could possibly use this issue to cause a denial
of service via catastrophic backtracking in the generated regular expressions.