{"id":"ECHO-e0a1-0205-5555","summary":"Fix multi-parameter ReDoS. Resets backtrack buffer to '' after\nconsuming a star or named-parameter token so subsequent parameters\ncan't extend a vulnerable backtrack pattern.\nBackported from https://github.com/pillarjs/path-to-regexp/commit/7ccf02cee33402f06ed2125085992ee9cd3a7c45\n(shipped upstream as 0.1.13). The index.js hunk is upstream verbatim;\nthe test.js hunk reuses upstream's test but is repositioned to apply\non top of GHSA-rhx6-c78j-4q9w's added test in v0.1.10's tree.\n","modified":"2026-09-15T03:33:35.227885508Z","published":"2026-07-01T11:55:48.881Z","withdrawn":"2026-05-07T14:20:44.772Z","upstream":["CVE-2026-4867","GHSA-37ch-88jc-xwx2"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/GHSA-37ch-88jc-xwx2"},{"type":"WEB","url":"https://github.com/advisories/GHSA-37ch-88jc-xwx2"}],"affected":[{"package":{"name":"path-to-regexp","ecosystem":"Echo:npm","purl":"pkg:npm/path-to-regexp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.10+echo.1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-e0a1-0205-5555.json"}}],"schema_version":"1.9.0"}