CVE-2026-4923
Impact:
When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that
Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path. Unsafe examples: /foo-bar-:baz /a-:b-c-:d /x/a-:b/c/y Safe examples: /foo-:bar /foo-:bar-*baz Patches: Upgrade to version 8.4.0.
Workarounds: If you are using multiple wildcard parameters, you can check the regex output with a tool such as https://makenowjust-labs.github.io/recheck/playground/ to confirm whether a path is vulnerable.
MEDIUM · CVSS 5.9
EPSS 0.00018
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0