{"id":"ECHO-8ffe-c246-e62c","upstream":["GHSA-rhx6-c78j-4q9w","CVE-2024-52798"],"severity":[],"modified":"2026-05-07T14:20:44.772Z","affected":[{"package":{"ecosystem":"Echo:npm","name":"path-to-regexp","purl":"pkg:npm/path-to-regexp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.10+echo.1"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/GHSA-rhx6-c78j-4q9w"},{"type":"WEB","url":"https://github.com/advisories/GHSA-rhx6-c78j-4q9w"}],"withdrawn":"2026-05-07T14:20:44.772Z","summary":"Fix backtracking protection. Adjusts pos/backtrack tracking inside the\npath replacer so backslash and dot matches don't reset the backtrack\nbuffer prematurely, preventing ReDoS via crafted inputs.\nBackported from https://github.com/pillarjs/path-to-regexp/commit/f01c26a013b1889f0c217c643964513acf17f6a4\n(shipped upstream as 0.1.12). The index.js hunk is upstream verbatim;\nthe test.js hunk reuses upstream's test but is repositioned to land\ninside v0.1.10's `describe('path-to-regexp', ...)` block (upstream's\ndiff context expected an intervening non-security commit not present\nin 0.1.10).\n"}