Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3506 | path-to-regexp contains a ReDoS |
Github GHSA |
GHSA-rhx6-c78j-4q9w | path-to-regexp contains a ReDoS |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 11 Jun 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat apache Camel Hawtio
|
|
| CPEs | cpe:/a:redhat:apache_camel_hawtio:4.2::el6 | |
| Vendors & Products |
Redhat rhboac Hawtio
|
Redhat apache Camel Hawtio
|
Tue, 10 Jun 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhboac Hawtio
|
|
| CPEs | cpe:/a:redhat:rhboac_hawtio:4 | |
| Vendors & Products |
Redhat rhboac Hawtio
|
Fri, 28 Mar 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift_ai:2.16::el8 cpe:/a:redhat:rhdh:1.5::el9 |
Fri, 21 Mar 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:rhdh:1.3::el9 |
Fri, 14 Feb 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift Ai
Redhat rhdh |
|
| CPEs | cpe:/a:redhat:openshift_ai:2.17::el8 cpe:/a:redhat:rhdh:1.4::el9 |
|
| Vendors & Products |
Redhat openshift Ai
Redhat rhdh |
Thu, 13 Feb 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat discovery Redhat openshift Redhat openshift Data Foundation Redhat service Mesh |
|
| CPEs | cpe:/a:redhat:openshift:4.17::el9 cpe:/a:redhat:openshift_data_foundation:4.16::el9 cpe:/a:redhat:openshift_data_foundation:4.17::el9 cpe:/a:redhat:service_mesh:2.5::el8 cpe:/o:redhat:discovery:1.0::el9 |
|
| Vendors & Products |
Redhat
Redhat discovery Redhat openshift Redhat openshift Data Foundation Redhat service Mesh |
Fri, 24 Jan 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 09 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pillarjs
Pillarjs path-to-regexp |
|
| CPEs | cpe:2.3:a:pillarjs:path-to-regexp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pillarjs
Pillarjs path-to-regexp |
|
| Metrics |
ssvc
|
Sat, 07 Dec 2024 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 05 Dec 2024 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path-to-regexp. Upgrade to 0.1.12. This vulnerability exists because of an incomplete fix for CVE-2024-45296. | |
| Title | path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x | |
| Weaknesses | CWE-1333 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-24T20:03:11.852Z
Reserved: 2024-11-15T17:11:13.440Z
Link: CVE-2024-52798
Updated: 2025-01-24T20:03:11.852Z
Status : Deferred
Published: 2024-12-05T23:15:06.310
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-52798
OpenCVE Enrichment
No data.
EUVD
Github GHSA