Skip to content

fix(deps): bump path-to-regexp 8.3.0 → 8.4.1 to patch ReDoS CVEs#576

Merged
ochafik merged 1 commit intomainfrom
claude/fix-path-to-regexp-alerts-hXoiu
Apr 1, 2026
Merged

fix(deps): bump path-to-regexp 8.3.0 → 8.4.1 to patch ReDoS CVEs#576
ochafik merged 1 commit intomainfrom
claude/fix-path-to-regexp-alerts-hXoiu

Conversation

@ochafik
Copy link
Copy Markdown
Contributor

@ochafik ochafik commented Mar 30, 2026

Summary

Bumps path-to-regexp from 8.3.0 to 8.4.1 to resolve two high-severity ReDoS vulnerabilities.

Vulnerabilities fixed

Dependency chain

express@5.2.1
└─ router@2.2.0
   └─ path-to-regexp@8.3.0 → 8.4.1

router@2.2.0 declares path-to-regexp: ^8.0.0, so this is a lockfile-only bump — no package.json changes needed.

Diff

3 lines in package-lock.json (version, resolved URL, integrity hash).

@pkg-pr-new
Copy link
Copy Markdown

pkg-pr-new bot commented Mar 30, 2026

Open in StackBlitz

@modelcontextprotocol/ext-apps

npm i https://pkg.pr.new/@modelcontextprotocol/ext-apps@576

@modelcontextprotocol/server-basic-preact

npm i https://pkg.pr.new/@modelcontextprotocol/server-basic-preact@576

@modelcontextprotocol/server-basic-react

npm i https://pkg.pr.new/@modelcontextprotocol/server-basic-react@576

@modelcontextprotocol/server-basic-solid

npm i https://pkg.pr.new/@modelcontextprotocol/server-basic-solid@576

@modelcontextprotocol/server-basic-svelte

npm i https://pkg.pr.new/@modelcontextprotocol/server-basic-svelte@576

@modelcontextprotocol/server-basic-vanillajs

npm i https://pkg.pr.new/@modelcontextprotocol/server-basic-vanillajs@576

@modelcontextprotocol/server-basic-vue

npm i https://pkg.pr.new/@modelcontextprotocol/server-basic-vue@576

@modelcontextprotocol/server-budget-allocator

npm i https://pkg.pr.new/@modelcontextprotocol/server-budget-allocator@576

@modelcontextprotocol/server-cohort-heatmap

npm i https://pkg.pr.new/@modelcontextprotocol/server-cohort-heatmap@576

@modelcontextprotocol/server-customer-segmentation

npm i https://pkg.pr.new/@modelcontextprotocol/server-customer-segmentation@576

@modelcontextprotocol/server-debug

npm i https://pkg.pr.new/@modelcontextprotocol/server-debug@576

@modelcontextprotocol/server-map

npm i https://pkg.pr.new/@modelcontextprotocol/server-map@576

@modelcontextprotocol/server-pdf

npm i https://pkg.pr.new/@modelcontextprotocol/server-pdf@576

@modelcontextprotocol/server-scenario-modeler

npm i https://pkg.pr.new/@modelcontextprotocol/server-scenario-modeler@576

@modelcontextprotocol/server-shadertoy

npm i https://pkg.pr.new/@modelcontextprotocol/server-shadertoy@576

@modelcontextprotocol/server-sheet-music

npm i https://pkg.pr.new/@modelcontextprotocol/server-sheet-music@576

@modelcontextprotocol/server-system-monitor

npm i https://pkg.pr.new/@modelcontextprotocol/server-system-monitor@576

@modelcontextprotocol/server-threejs

npm i https://pkg.pr.new/@modelcontextprotocol/server-threejs@576

@modelcontextprotocol/server-transcript

npm i https://pkg.pr.new/@modelcontextprotocol/server-transcript@576

@modelcontextprotocol/server-video-resource

npm i https://pkg.pr.new/@modelcontextprotocol/server-video-resource@576

@modelcontextprotocol/server-wiki-explorer

npm i https://pkg.pr.new/@modelcontextprotocol/server-wiki-explorer@576

commit: b379b73

Transitive dep via express → router. Fixes:
- GHSA-27v5-c462-wpq7 (ReDoS via multiple wildcards)
- GHSA-j3q9-mxjg-w52f (DoS via sequential optional groups)

router@2.2.0 accepts ^8.0.0, so this is a clean lockfile-only bump.
@ochafik ochafik force-pushed the claude/fix-path-to-regexp-alerts-hXoiu branch from d51cf3b to b379b73 Compare April 1, 2026 16:55
@ochafik ochafik changed the title Add Claude settings file to gitignore fix(deps): bump path-to-regexp 8.3.0 → 8.4.1 to patch ReDoS CVEs Apr 1, 2026
@ochafik ochafik changed the base branch from feat/app-tool-registration to main April 1, 2026 16:59
@ochafik ochafik marked this pull request as ready for review April 1, 2026 17:03
@ochafik ochafik merged commit f987bc4 into main Apr 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant