WhisperX tag archive

#CVE-2026-4867

This page collects WhisperX intelligence signals tagged #CVE-2026-4867. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-03-28 00:27:09 · GitHub Issues

1. Critical CVE-2026-4867 in Express.js 4.22.1: High-Severity Path-to-Regexp Vulnerability Exposes Projects

A high-severity vulnerability, CVE-2026-4867, has been identified in the widely used Express.js framework version 4.22.1. The flaw, with a CVSS score of 7.5, resides in the `path-to-regexp` dependency, a core library for parsing URL paths. This security gap exposes any application built on this specific version of Expr...

The Lab · 2026-04-08 10:27:09 · GitHub Issues

2. CVE-2026-4867: High-Severity ReDoS Vulnerability in path-to-regexp v0.1.7 Exposes Express.js Applications

A high-severity Regular Expression Denial of Service (ReDoS) vulnerability, tracked as CVE-2026-4867, has been identified in the legacy `path-to-regexp` npm package version 0.1.7. This utility, a core component for parsing URL paths in the Express.js web framework, contains a flawed regex generator that can be exploite...