ECHO-8ffe-c246-e62c

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-8ffe-c246-e62c.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-8ffe-c246-e62c
Upstream
Withdrawn
2026-05-07T14:20:44.772Z
Published
2026-05-07T14:20:44.772Z
Modified
2026-07-20T18:23:29.798283589Z
Summary
Fix backtracking protection. Adjusts pos/backtrack tracking inside the path replacer so backslash and dot matches don't reset the backtrack buffer prematurely, preventing ReDoS via crafted inputs. Backported from https://github.com/pillarjs/path-to-regexp/commit/f01c26a013b1889f0c217c643964513acf17f6a4 (shipped upstream as 0.1.12). The index.js hunk is upstream verbatim; the test.js hunk reuses upstream's test but is repositioned to land inside v0.1.10's `describe('path-to-regexp', ...)` block (upstream's diff context expected an intervening non-security commit not present in 0.1.10).
Details
References

Affected packages

Echo:npm / path-to-regexp

Package

Name
path-to-regexp
Purl
pkg:npm/path-to-regexp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.10+echo.1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-8ffe-c246-e62c.json"