ECHO-e0a1-0205-5555

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-e0a1-0205-5555.json
JSON Data
https://api.test.osv.dev/v1/vulns/ECHO-e0a1-0205-5555
Upstream
Withdrawn
2026-05-07T14:20:44Z
Published
2026-07-01T11:55:48Z
Modified
2026-09-15T00:47:33Z
Summary
Fix multi-parameter ReDoS. Resets backtrack buffer to '' after consuming a star or named-parameter token so subsequent parameters can't extend a vulnerable backtrack pattern. Backported from https://github.com/pillarjs/path-to-regexp/commit/7ccf02cee33402f06ed2125085992ee9cd3a7c45 (shipped upstream as 0.1.13). The index.js hunk is upstream verbatim; the test.js hunk reuses upstream's test but is repositioned to apply on top of GHSA-rhx6-c78j-4q9w's added test in v0.1.10's tree.
Details
References

Affected packages

Echo:npm / path-to-regexp

Package

Name
path-to-regexp
Purl
pkg:npm/path-to-regexp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.1.10+echo.1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-e0a1-0205-5555.json"