{"id":"ECHO-e0a1-0205-5555","upstream":["GHSA-37ch-88jc-xwx2","CVE-2026-4867"],"severity":[],"modified":"2026-05-07T14:20:44.772Z","affected":[{"package":{"ecosystem":"Echo:npm","name":"path-to-regexp","purl":"pkg:npm/path-to-regexp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.10+echo.1"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/GHSA-37ch-88jc-xwx2"},{"type":"WEB","url":"https://github.com/advisories/GHSA-37ch-88jc-xwx2"}],"withdrawn":"2026-05-07T14:20:44.772Z","summary":"Fix multi-parameter ReDoS. Resets backtrack buffer to '' after\nconsuming a star or named-parameter token so subsequent parameters\ncan't extend a vulnerable backtrack pattern.\nBackported from https://github.com/pillarjs/path-to-regexp/commit/7ccf02cee33402f06ed2125085992ee9cd3a7c45\n(shipped upstream as 0.1.13). The index.js hunk is upstream verbatim;\nthe test.js hunk reuses upstream's test but is repositioned to apply\non top of GHSA-rhx6-c78j-4q9w's added test in v0.1.10's tree.\n"}