OsVault/npm/express
npm3 critical

express

300 known vulnerabilities · 3 critical · 94 high

CVE-2024-43796MEDIUM

express vulnerable to XSS via response.redirect()

Published Sep 10, 2024
CVE-2014-6393MEDIUM

No Charset in Content-Type Header in express

Published Oct 23, 2018
CVE-2024-51999

Withdrawn Advisory: express improperly controls modification of query properties

Published Dec 1, 2025
CVE-2024-29041MEDIUM

Express.js Open Redirect in malformed URLs

Published Mar 25, 2024
MAL-2025-190961

Malicious code in expressos (npm)

Published Nov 24, 2025
CVE-2023-26118MEDIUM

angular vulnerable to regular expression denial of service via the <input type="url"> element

Published Mar 30, 2023
CVE-2026-4923

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards

Published Mar 27, 2026
CVE-2022-37262HIGH

steal vulnerable to Regular Expression Denial of Service via source and sourceWithComments

Published Sep 16, 2022
CVE-2020-28500MEDIUM

Regular Expression Denial of Service (ReDoS) in lodash

Published Jan 6, 2022
CVE-2024-27088

es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`

Published Feb 26, 2024
CVE-2023-23630HIGH

XSS Attack with Express API

Published Jan 31, 2023
CVE-2021-43307MEDIUM

Regular expression denial of service in semver-regex

Published Jun 3, 2022
CVE-2020-7755HIGH

Regular Expression Denial of Service in dat.gui

Published May 10, 2021
CVE-2021-26073HIGH

Broken Authentication in Atlassian Connect Express

Published May 24, 2022
MAL-2026-1062

Malicious code in express-core-validator (npm)

Published Feb 27, 2026
GHSA-2qqc-p94c-hxwh

Flowise: Weak Default Express Session Secret

Published Apr 16, 2026
CVE-2017-20160MEDIUM

express-param vulnerable to Improper Handling of Extra Parameters

Published Dec 31, 2022
CVE-2021-23354MEDIUM

printf vulnerable to Regular Expression Denial of Service (ReDoS)

Published Mar 19, 2021
CVE-2018-7651MEDIUM

Regular Expression Denial of Service in ssri

Published Mar 7, 2018
CVE-2026-1615

jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Expressions

Published Feb 9, 2026
CVE-2016-4055MEDIUM

Regular Expression Denial of Service in moment

Published Oct 24, 2017
CVE-2016-10520HIGH

Regular Expression Denial of Service in jadedown

Published Feb 18, 2019
CVE-2017-16098HIGH

Regular Expression Denial of Service in charset

Published Aug 9, 2018
CVE-2021-21306MEDIUM

Regular Expression Denial of Service (REDoS) in Marked

Published Feb 8, 2021
MAL-2026-2419

Malicious code in express-session-js (npm)

Published Apr 2, 2026
CVE-2025-26042

Uptime Kuma's Regular Expression in pushdeeer and whapi file Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Mar 31, 2025
CVE-2026-4867

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters

Published Mar 27, 2026
CVE-2026-33979

Express XSS Sanitizer: allowedTags/allowedAttributes bypass leads to permissive sanitization (XSS risk)

Published Mar 27, 2026
CVE-2017-16118HIGH

Regular Expression Denial of Service in forwarded

Published Jul 24, 2018
CVE-2020-7779MEDIUM

Regular Expression Denial of Service in djvalidator

Published Feb 9, 2022
CVE-2026-33713

n8n has SQL Injection in Data Table Node via orderByColumn Expression

Published Mar 26, 2026
MAL-2025-61

Malicious code in express-v4 (npm)

Published Jan 5, 2025
CVE-2020-26309

nope-validator Regular Expression Denial of Service vulnerability

Published Oct 26, 2024
CVE-2020-7699HIGH

Prototype Pollution in express-fileupload

Published Aug 5, 2020
CVE-2021-3807HIGH

Inefficient Regular Expression Complexity in chalk/ansi-regex

Published Sep 20, 2021
CVE-2024-21538HIGH

Regular Expression Denial of Service (ReDoS) in cross-spawn

Published Nov 8, 2024
CVE-2015-8858HIGH

Regular Expression Denial of Service in uglify-js

Published Oct 24, 2017
CVE-2018-1107MEDIUM

Regular expression deinal of service (ReDoS) in is-my-json-valid

Published Jan 6, 2022
CVE-2017-18214HIGH

Regular Expression Denial of Service in moment

Published Mar 5, 2018
CVE-2018-25061MEDIUM

rgb2hex vulnerable to inefficient regular expression complexity

Published Dec 31, 2022
CVE-2023-23925HIGH

Switcher Client contains Regular Expression Denial of Service (ReDoS)

Published Feb 2, 2023
CVE-2020-7754HIGH

Regular expression denial of service in npm-user-validate

Published May 10, 2021
CVE-2021-3810HIGH

Inefficient Regular Expression Complexity in code-server

Published Sep 20, 2021
CVE-2017-16099HIGH

Regular Expression Denial of Service in no-case

Published Jul 24, 2018
CVE-2023-39619HIGH

Inefficient Regular Expression Complexity in node-email-check

Published Oct 25, 2023
CVE-2026-22809

tarteaucitron.js has Regular Expression Denial of Service (ReDoS) vulnerability

Published Jan 13, 2026
CVE-2025-25285

@octokit/endpoint has a Regular Expression in parse that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Feb 14, 2025
CVE-2017-20165LOW

debug Inefficient Regular Expression Complexity vulnerability

Published Jan 9, 2023
CVE-2016-10521HIGH

Regular Expression Denial of Service in jshamcrest

Published Feb 18, 2019
CVE-2022-27261HIGH

Express-FileUpload Arbitrary File Overwrite

Published Apr 13, 2022
CVE-2025-25288

@octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Feb 14, 2025
CVE-2019-10758CRITICAL

Remote Code Execution Vulnerability in NPM mongo-express

Published Dec 30, 2019
CVE-2022-35923HIGH

v8n vulnerable to Inefficient Regular Expression Complexity

Published Oct 7, 2022
CVE-2020-7753HIGH

Regular Expression Denial of Service in trim

Published May 10, 2021
CVE-2026-32770

Parse Server LiveQuery subscription with invalid regular expression crashes server

Published Mar 17, 2026
CVE-2021-23346MEDIUM

html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS)

Published Mar 18, 2021
CVE-2015-10005LOW

markdown-it vulnerable to Inefficient Regular Expression Complexity

Published Dec 27, 2022
CVE-2021-43838MEDIUM

Regular Expression Denial of Service (ReDoS) in jsx-slack

Published Dec 17, 2021
CVE-2021-23382MEDIUM

Regular Expression Denial of Service in postcss

Published Jan 7, 2022
CVE-2020-28501MEDIUM

Regular Expression Denial of Service (ReDoS) in es6-crawler-detect

Published Apr 13, 2021
CVE-2019-17592HIGH

Regular Expression Denial of Service in csv-parse

Published Oct 15, 2019
CVE-2019-1010266MEDIUM

Regular Expression Denial of Service (ReDoS) in lodash

Published Jul 19, 2019
CVE-2026-30925

Parse Server has Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery

Published Mar 10, 2026
GHSA-6hw5-45gm-fj88

@fastify/express has a middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)

Published Apr 16, 2026
CVE-2018-7560HIGH

AWS Lambda parser is vulnerable to Regular Expression Denial of Service

Published Mar 5, 2018
MAL-2026-2771

Malicious code in icims-express-dot-engine (npm)

Published Apr 16, 2026
CVE-2022-25844MEDIUM

angular vulnerable to regular expression denial of service (ReDoS)

Published May 3, 2022
CVE-2014-8881

Regular Expression Denial of Service in bleach

Published Sep 1, 2020
CVE-2022-37260HIGH

steal vulnerable to Regular Expression Denial of Service via input variable

Published Sep 16, 2022
MAL-2022-1392

Malicious code in azure-web-pubsub-express (npm)

Published Jun 20, 2022
CVE-2018-12457HIGH

express-cart allows any user to create an admin user

Published May 13, 2022
CVE-2021-4299MEDIUM

string-kit Inefficient Regular Expression Complexity vulnerability

Published Jan 2, 2023
CVE-2018-25079MEDIUM

is-url Inefficient Regular Expression Complexity vulnerability

Published Feb 4, 2023
CVE-2024-22363HIGH

SheetJS Regular Expression Denial of Service (ReDoS)

Published Apr 5, 2024
CVE-2020-24391CRITICAL

Remote code execution in mongo-express

Published Apr 13, 2021
CVE-2018-25074LOW

skeemas Inefficient Regular Expression Complexity vulnerability

Published Jan 11, 2023
CVE-2020-26289HIGH

regular expression denial of service (ReDoS)

Published Dec 24, 2020
CVE-2026-1470

n8n Unsafe Workflow Expression Evaluation Allows Remote Code Execution

Published Jan 27, 2026
CVE-2022-23624HIGH

Validation bypass in frourio-express

Published Feb 7, 2022
CVE-2020-7733HIGH

Regular Expression Denial of Service in ua-parser-js

Published May 7, 2021
CVE-2015-9239HIGH

Regular Expression Denial of Service in ansi2html

Published Sep 1, 2020
CVE-2021-23388MEDIUM

Regular expression denial of service in forms

Published Jun 7, 2021
CVE-2020-7616MEDIUM

Improperly Controlled Modification of Dynamically-Determined Object Attributes in express-mock-middleware

Published Dec 9, 2021
CVE-2018-25077LOW

mel-spintax has Inefficient Regular Expression Complexity

Published Jan 18, 2023
CVE-2021-4305LOW

robots-txt-guard Inefficient Regular Expression Complexity vulnerability

Published Jan 5, 2023
CVE-2020-15084HIGH

Authorization bypass in express-jwt

Published Jun 30, 2020
CVE-2023-24807HIGH

Regular Expression Denial of Service in Headers

Published Feb 16, 2023
CVE-2021-32821MEDIUM

MooTools Regular Expression Denial of Service

Published Jan 3, 2023
CVE-2025-5889

brace-expansion Regular Expression Denial of Service vulnerability

Published Jun 9, 2025
MAL-2022-2230

Malicious code in create-ot-express-app (npm)

Published Jul 26, 2022
CVE-2022-31129HIGH

Moment.js vulnerable to Inefficient Regular Expression Complexity

Published Jul 6, 2022
CVE-2026-27493

n8n has Unauthenticated Expression Evaluation via Form Node

Published Feb 25, 2026
CVE-2021-27292HIGH

Regular Expression Denial of Service (ReDoS) in ua-parser-js

Published May 6, 2021
CVE-2021-4306LOW

terminal-kit Inefficient Regular Expression Complexity vulnerability

Published Jan 7, 2023
CVE-2025-29907

jsPDF Bypass Regular Expression Denial of Service (ReDoS)

Published Mar 18, 2025
CVE-2021-3820HIGH

inflect vulnerable to Inefficient Regular Expression Complexity

Published Sep 29, 2021
CVE-2020-1920HIGH

Regular expression denial of service in react-native

Published Jul 20, 2021
CVE-2015-8855HIGH

Regular Expression Denial of Service in semver

Published Oct 24, 2017
CVE-2026-34211HIGH
Risk: 50.42/100

SandboxJS: Stack overflow DoS via deeply nested expressions in recursive descent parser

Published Apr 3, 2026
CVE-2016-10539HIGH

Regular Expression Denial of Service in negotiator

Published Oct 9, 2018
CVE-2022-24794HIGH

URL Redirection to Untrusted Site ('Open Redirect') in express-openid-connect

Published Mar 31, 2022
CVE-2024-21539HIGH

Regular Expression Denial of Service (ReDoS) in @eslint/plugin-kit

Published Nov 15, 2024
CVE-2021-28092HIGH

Regular Expression Denial of Service (ReDoS)

Published Mar 19, 2021
CVE-2025-65110

Vega XSS via expression abusing vlSelectionTuples function array map calls in environments with satisfactory function gadgets in the global scope

Published Jan 5, 2026
CVE-2025-25289

@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Feb 14, 2025
CVE-2022-37603HIGH

loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) via url variable

Published Oct 14, 2022
CVE-2024-4067MEDIUM

Regular Expression Denial of Service (ReDoS) in micromatch

Published May 14, 2024
CVE-2021-23362MEDIUM

Regular Expression Denial of Service in hosted-git-info

Published May 6, 2021
CVE-2021-3795HIGH

semver-regex Regular Expression Denial of Service (ReDOS)

Published Sep 20, 2021
CVE-2020-7760MEDIUM

Regular expression denial of service in codemirror

Published May 10, 2021
CVE-2021-27405HIGH

Regular expression Denial of Service in @progfay/scrapbox-parser

Published Mar 1, 2021
MAL-2022-6389

Malicious code in sync-express (npm)

Published Jun 8, 2022
CVE-2023-26486MEDIUM

Vega Expression Language `scale` expression function Cross Site Scripting

Published Mar 2, 2023
CVE-2026-30827

express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network

Published Mar 6, 2026
CVE-2021-41246MEDIUM

Session fixation in express-openid-connect

Published Dec 9, 2021
CVE-2022-2596MEDIUM

node-fetch Inefficient Regular Expression Complexity

Published Aug 2, 2022
CVE-2021-23368MEDIUM

Regular Expression Denial of Service in postcss

Published May 10, 2021
MAL-2025-191089

Malicious code in express-starter-template (npm)

Published Nov 24, 2025
CVE-2022-25883MEDIUM

semver vulnerable to Regular Expression Denial of Service

Published Jun 21, 2023
CVE-2022-21681HIGH

Inefficient Regular Expression Complexity in marked

Published Jan 14, 2022
CVE-2021-3777HIGH

tmpl vulnerable to Inefficient Regular Expression Complexity which may lead to resource exhaustion

Published Sep 20, 2021
CVE-2017-16114HIGH

Regular Expression Denial of Service in marked

Published Jul 24, 2018
MAL-2025-190693

Malicious code in bool-expressions (npm)

Published Nov 24, 2025
CVE-2017-16119HIGH

Regular Expression Denial of Service in fresh

Published Jul 24, 2018
GHSA-g95f-p29q-9xw4

Duplicate Advisory: Regular Expression Denial of Service in braces

Published Jun 6, 2019
MAL-2023-946

Malicious code in vscode-smoketest-express (npm)

Published Jan 30, 2023
CVE-2020-22403HIGH

Cross-Site Request Forgery in express-cart

Published Aug 30, 2021
CVE-2021-21267HIGH

Regular Expression Denial-of-Service in npm schema-inspector

Published Mar 19, 2021
CVE-2023-25166MEDIUM

@sideway/formula contains Regular Expression Denial of Service (ReDoS) Vulnerability

Published Feb 8, 2023
MAL-2024-933

Malicious code in iifl_express_middleware (npm)

Published Jan 29, 2024
CVE-2020-7767MEDIUM

Regular expression deinal of service in express-validators

Published May 10, 2021
CVE-2023-48631MEDIUM

@adobe/css-tools Improper Input Validation and Inefficient Regular Expression Complexity

Published Nov 30, 2023
CVE-2021-23372MEDIUM

Denial of Service (DoS) in mongo-express

Published Oct 6, 2021
CVE-2021-3749HIGH

axios Inefficient Regular Expression Complexity vulnerability

Published Sep 1, 2021
CVE-2022-25918MEDIUM

Inefficient Regular Expression Complexity in shescape

Published Oct 25, 2022
CVE-2017-16115HIGH

Regular Expression Denial of Service in timespan

Published Aug 29, 2018
CVE-2022-31147HIGH

jquery-validation Regular Expression Denial of Service due to arbitrary input to url2 method

Published Jul 5, 2022
MAL-2024-8951

Malicious code in express-request-ip (npm)

Published Sep 23, 2024
CVE-2022-1929MEDIUM

Regular expression denial of service in devcert

Published Jun 3, 2022
CVE-2024-27307CRITICAL

JSONata expression can pollute the "Object" prototype

Published Mar 4, 2024
GHSA-7gcj-phff-2884

Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription Paths

Published Apr 21, 2026
CVE-2022-25758MEDIUM

Regular expression denial of service in scss-tokenizer

Published Jul 2, 2022
CVE-2016-2515HIGH

Regular Expression Denial of Service in hawk

Published Jul 31, 2018
CVE-2021-32820HIGH

Insecure template handling in Express-handlebars

Published Feb 10, 2022
CVE-2020-28469MEDIUM

glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex

Published Jun 7, 2021
CVE-2021-23343MEDIUM

Regular Expression Denial of Service in path-parse

Published Aug 10, 2021
CVE-2020-26308HIGH

validate.js Regular Expression Denial of Service vulnerability

Published Oct 26, 2024
CVE-2020-5219HIGH

Remote Code Execution in Angular Expressions

Published Jan 24, 2020
CVE-2026-22037

@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)

Published Jan 20, 2026
CVE-2019-25102MEDIUM

Regular Expression Denial of Service in simple-markdown

Published Feb 12, 2023
CVE-2020-7662HIGH

Regular Expression Denial of Service in websocket-extensions (NPM package)

Published Jun 5, 2020
CVE-2022-36034HIGH

Polynomial regular expression used on uncontrolled data in nitrado.js

Published Aug 31, 2022
CVE-2016-10540HIGH

Regular Expression Denial of Service in minimatch

Published Oct 9, 2018
CVE-2017-16138HIGH

mime Regular Expression Denial of Service when MIME lookup performed on untrusted user input

Published Jul 20, 2018
CVE-2021-32723HIGH

Regular Expression Denial of Service (ReDoS) in Prism

Published Jun 28, 2021
MAL-2026-1012

Malicious code in ultimates-express (npm)

Published Feb 24, 2026
CVE-2019-25103MEDIUM

Regular Expression Denial of Service in simple-markdown

Published Feb 12, 2023
CVE-2018-3758HIGH

express-cart unrestricted file upload vulnerability

Published May 13, 2022
CVE-2023-26364MEDIUM

@adobe/css-tools Regular Expression Denial of Service (ReDOS) while Parsing CSS

Published Aug 29, 2023
MAL-2026-1570

Malicious code in transform-member-expression-literals (npm)

Published Mar 16, 2026
CVE-2025-4727

Meteor Affected By Inefficient Regular Expression Complexity

Published May 16, 2025
CVE-2014-8882

Regular Expression Denial of Service in validator

Published Aug 31, 2020
CVE-2021-21252MEDIUM

Regular Expression Denial of Service in jquery-validation

Published Jan 13, 2021
MAL-2025-66549

Malicious code in swagger-express-evaluator (npm)

Published Nov 11, 2025
CVE-2018-20164MEDIUM

uap-core Regular Expression Denial of Service issue

Published Mar 6, 2019
CVE-2017-16116HIGH

Regular Expression Denial of Service in string package

Published Jul 24, 2018
CVE-2016-10527HIGH

Regular Expression Denial of Service in riot-compiler

Published Feb 18, 2019
CVE-2020-26302HIGH

is_js vulnerable to Regular Expression Denial of Service

Published Jul 6, 2023
CVE-2021-21254MEDIUM

CKEditor 5 Markdown plugin Regular expression Denial of Service

Published Jan 29, 2021
CVE-2020-7761MEDIUM

Regular expression denial of service in @absolunet/kafe

Published May 10, 2021
CVE-2021-3822HIGH

Regular Expression Denial of Service in jsoneditor

Published Sep 29, 2021
CVE-2022-21169HIGH

express-xss-sanitizer vulnerable to Prototype Pollution via allowedTags attribute

Published Sep 27, 2022
GHSA-h6ch-v84p-w6p9

Regular Expression Denial of Service (ReDoS)

Published Jun 13, 2019
CVE-2021-23446HIGH

Inefficient Regular Expression Complexity in handsontable

Published Sep 30, 2021
MAL-2025-3255

Malicious code in helper-member-expression-to-functions (npm)

Published Apr 17, 2025
CVE-2017-16113HIGH

Regular Expression Denial of Service in parsejson

Published Jul 24, 2018
GHSA-wx77-rp39-c6vg

Regular Expression Denial of Service in markdown

Published Sep 4, 2020
GHSA-hrwm-hgmj-7p9c

@fastify/express's middleware path doubling causes authentication bypass in child plugin scopes

Published Apr 16, 2026
MAL-2022-3869

Malicious code in internal_crypto_express_package (npm)

Published Jun 20, 2022
MAL-2025-3681

Malicious code in express-cronjs (npm)

Published May 7, 2025
CVE-2022-25881MEDIUM

http-cache-semantics vulnerable to Regular Expression Denial of Service

Published Jan 31, 2023
CVE-2017-16111HIGH

Regular Expression Denial of Service in content

Published Jul 24, 2018
MAL-2026-2445

Malicious code in pro-express (npm)

Published Apr 2, 2026
MAL-2026-514

Malicious code in overstock-health-express (npm)

Published Jan 23, 2026
CVE-2020-36649LOW

Regular Expression Denial of Service in papaparse

Published Sep 4, 2020
CVE-2017-16117HIGH

Regular Expression Denial of Service in slug

Published Jul 24, 2018
CVE-2025-67731

Servify-express rate limit issue

Published Dec 11, 2025
CVE-2025-59364

express-xss-sanitizer has an unbounded recursion depth

Published Sep 26, 2025
MAL-2026-2358

Malicious code in env-cli-express (npm)

Published Mar 24, 2026
CVE-2023-39663HIGH

MathJax Regular expression Denial of Service (ReDoS)

Published Aug 29, 2023
CVE-2021-3794HIGH

Inefficient Regular Expression Complexity in vuelidate

Published Sep 20, 2021
GHSA-4xf9-pgvv-xx67

Duplicate Advisory: Regular Expression Denial of Service in simple-markdown

Published Sep 3, 2020
GHSA-xffm-g5w8-qvg7

@eslint/plugin-kit is vulnerable to Regular Expression Denial of Service attacks through ConfigCommentParser

Published Jul 18, 2025
MAL-2025-191188

Malicious code in @antstackio/express-graphql-proxy (npm)

Published Nov 25, 2025
MAL-2025-192350

Malicious code in express-my-error-handler (npm)

Published Dec 6, 2025
CVE-2021-27290HIGH

Regular Expression Denial of Service (ReDoS)

Published Mar 19, 2021
CVE-2023-26116MEDIUM

angular vulnerable to regular expression denial of service via the angular.copy() utility

Published Mar 30, 2023
CVE-2022-37259HIGH

steal Inefficient Regular Expression Complexity vulnerability via string variable

Published Sep 21, 2022
CVE-2025-25290

@octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Feb 14, 2025
MAL-2022-2931

Malicious code in expressyession (npm)

Published Aug 19, 2022
CVE-2018-20801HIGH

Regular Expression Denial of Service in highcharts

Published Mar 18, 2019
CVE-2025-25200

Inefficient Regular Expression Complexity in koa

Published Feb 12, 2025
CVE-2023-22467HIGH

Luxon Inefficient Regular Expression Complexity vulnerability

Published Jan 9, 2023
CVE-2021-3804HIGH

Inefficient Regular Expression Complexity in taro

Published Sep 20, 2021
MAL-2026-1106

Malicious code in expressjs-lint (npm)

Published Mar 2, 2026
CVE-2022-25858MEDIUM

Terser insecure use of regular expressions leads to ReDoS

Published Jul 16, 2022
CVE-2021-23353MEDIUM

jspdf vulnerable to Regular Expression Denial of Service (ReDoS)

Published Mar 12, 2021
MAL-2022-2924

Malicious code in express-4.x-passport-snapchat-example (npm)

Published Jun 20, 2022
CVE-2021-3801MEDIUM

prismjs Regular Expression Denial of Service vulnerability

Published Sep 20, 2021
CVE-2017-15010HIGH

Regular Expression Denial of Service in tough-cookie

Published Jul 24, 2018
CVE-2021-21277HIGH

Angular Expressions - Remote Code Execution

Published Feb 1, 2021
CVE-2025-5896

taro-css-to-react-native Regular Expression Denial of Service vulnerability

Published Jun 9, 2025
CVE-2021-43308MEDIUM

Regular expression denial of service in markdown-link-extractor

Published Jun 3, 2022
MAL-2025-48439

Malicious code in swagger-express-cli (npm)

Published Oct 17, 2025
MAL-2026-833

Malicious code in express-configer (npm)

Published Feb 10, 2026
CVE-2026-35213
Risk: 44.38/100

@hapi/content: Regular Expression Denial of Service (ReDoS) in HTTP header parsing

Published Apr 4, 2026
MAL-2022-1681

Malicious code in brightspot-express (npm)

Published Jun 20, 2022
MAL-2025-4683

Malicious code in express-api-sync (npm)

Published Jun 4, 2025
CVE-2026-27904

minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Published Feb 26, 2026
CVE-2026-2327

markdown-it is has a Regular Expression Denial of Service (ReDoS)

Published Feb 12, 2026
CVE-2025-5891

pm2 Regular Expression Denial of Service vulnerability

Published Jun 9, 2025
CVE-2020-7793HIGH

ua-parser-js Regular Expression Denial of Service vulnerability

Published Feb 9, 2022
CVE-2018-25110HIGH

Marked allows Regular Expression Denial of Service (ReDoS) attacks

Published May 23, 2025
MAL-2022-7074

Malicious code in web-pubsub-express (npm)

Published Jun 20, 2022
CVE-2022-21680HIGH

Inefficient Regular Expression Complexity in marked

Published Jan 14, 2022
MAL-2022-7043

Malicious code in walmart-express (npm)

Published Jul 21, 2022
MAL-2025-3551

Malicious code in express-validator-plugin (npm)

Published Apr 30, 2025
CVE-2025-5897

@vue/cli-plugin-pwa Regular Expression Denial of Service vulnerability

Published Jun 9, 2025
CVE-2017-16009MEDIUM

XSS via Angular Expression in ag-grid

Published Sep 1, 2020
CVE-2018-1109MEDIUM

Regular Expression Denial of Service (ReDoS) in braces

Published Jan 6, 2022
CVE-2022-25901MEDIUM

cookiejar Regular Expression Denial of Service via Cookie.parse function

Published Jan 18, 2023
MAL-2022-1547

Malicious code in bfx-report-express (npm)

Published Jun 20, 2022
CVE-2018-25049LOW

email-existence Inefficient Regular Expression Complexity vulnerability

Published Dec 27, 2022
CVE-2021-23364MEDIUM

Regular Expression Denial of Service in browserslist

Published May 24, 2021
CVE-2021-3765HIGH

Inefficient Regular Expression Complexity in validator.js

Published Nov 3, 2021
MAL-2025-1586

Malicious code in falcor-express-demo (npm)

Published Feb 28, 2025
GHSA-xgh6-85xh-479p

Regular Expression Denial of Service in npm-user-validate

Published Oct 16, 2020
MAL-2025-47932

Malicious code in swagger-cli-express (npm)

Published Oct 7, 2025
CVE-2021-3803HIGH

Inefficient Regular Expression Complexity in nth-check

Published Sep 20, 2021
MAL-2025-4109

Malicious code in node-express-demo (npm)

Published May 21, 2025
CVE-2021-32817MEDIUM

Insecure template handling in express-hbs

Published May 17, 2021
MAL-2024-9052

Malicious code in express-dompurify (npm)

Published Oct 1, 2024
MAL-2026-2828

Malicious code in express-security-policy (npm)

Published Apr 17, 2026
MAL-2022-2022

Malicious code in colors_express (npm)

Published May 31, 2022
MAL-2026-2128

Malicious code in express-session-vailidator (npm)

Published Mar 24, 2026
MAL-2026-751

Malicious code in express_update (npm)

Published Feb 5, 2026
MAL-2026-722

Malicious code in express-groups-routes (npm)

Published Feb 4, 2026
MAL-2023-320

Malicious code in express-http-geobase (npm)

Published Jan 30, 2023
MAL-2023-321

Malicious code in express-http-langdetect (npm)

Published Jan 30, 2023
MAL-2022-2925

Malicious code in express-blackbox (npm)

Published Jun 20, 2022
MAL-2022-2926

Malicious code in express-checkout-sdk (npm)

Published Jun 20, 2022
MAL-2022-2927

Malicious code in express-lastest (npm)

Published May 31, 2022
MAL-2022-2928

Malicious code in express-metrics-zmarta (npm)

Published Jun 20, 2022
MAL-2022-2929

Malicious code in express-uatraits (npm)

Published Jun 20, 2022
MAL-2022-2930

Malicious code in express-yandexuid (npm)

Published Jun 20, 2022
MAL-2025-192968

Malicious code in express-js-web (npm)

Published Dec 30, 2025
MAL-2026-1009

Malicious code in express-soaps (npm)

Published Feb 24, 2026
MAL-2025-2257

Malicious code in example-nodejs-express (npm)

Published Mar 11, 2025
MAL-2026-2129

Malicious code in express-session-validator (npm)

Published Mar 24, 2026
MAL-2026-2759

Malicious code in express-auth-basic (npm)

Published Apr 16, 2026
MAL-2026-1549

Malicious code in syntax-do-expressions (npm)

Published Mar 16, 2026
MAL-2026-2901

Malicious code in env_express (npm)

Published Apr 15, 2026
MAL-2025-4829

Malicious code in express-jscookie (npm)

Published Jun 10, 2025
CVE-2019-20922HIGH

Regular Expression Denial of Service in Handlebars

Published Feb 10, 2022
MAL-2024-2035

Malicious code in cta-onboard-express (npm)

Published Jun 25, 2024
MAL-2026-1730

Malicious code in express-configers (npm)

Published Mar 18, 2026
MAL-2022-5242

Malicious code in paypal-express (npm)

Published Jun 20, 2022
MAL-2025-190683

Malicious code in @trigo/bool-expressions (npm)

Published Nov 24, 2025
MAL-2023-322

Malicious code in expressautomations (npm)

Published Jul 24, 2023
MAL-2023-346

Malicious code in fc-expressions (npm)

Published Jun 6, 2023
MAL-2026-1732

Malicious code in express-ranges (npm)

Published Mar 18, 2026
MAL-2026-1733

Malicious code in express-security-suite-2024 (npm)

Published Mar 18, 2026
MAL-2026-218

Malicious code in express-sessions-id (npm)

Published Jan 12, 2026
MAL-2024-9133

Malicious code in braintree_express_example (npm)

Published Oct 9, 2024
MAL-2022-3345

Malicious code in geocaching-express-account-middleware (npm)

Published Nov 17, 2022
CVE-2020-7661HIGH

Regular expression denial of service in url-regex

Published Jun 22, 2020
MAL-2025-3238

Malicious code in express-exp (npm)

Published Apr 17, 2025
MAL-2024-9077

Malicious code in express-core-cache (npm)

Published Oct 2, 2024
CVE-2021-29060MEDIUM

Regular Expression Denial of Service (ReDOS)

Published Jun 22, 2021
CVE-2018-3737HIGH

Regular Expression Denial of Service in sshpk

Published Aug 15, 2018
CVE-2023-26117MEDIUM

angular vulnerable to regular expression denial of service via the $resource service

Published Mar 30, 2023
GHSA-3fc5-9x9m-vqc4

Duplicate Advisory: Privilege Escalation in express-cart

Published Jun 3, 2019
CVE-2020-26306

Knwl.js Regular Expression Denial of Service vulnerability

Published Oct 26, 2024
CVE-2024-45296HIGH

path-to-regexp outputs backtracking regular expressions

Published Sep 9, 2024
CVE-2016-10533HIGH

Private Data Disclosure in express-restify-mongoose

Published Oct 23, 2018
CVE-2021-43309MEDIUM

uri-template-lite Regular Expression Denial of Service

Published Aug 25, 2022
CVE-2017-16137MEDIUM

Regular Expression Denial of Service in debug

Published Aug 9, 2018
CVE-2017-16023HIGH

Regular Expression Denial of Service in decamelize

Published Jul 24, 2018
CVE-2021-21391MEDIUM

Regular expression Denial of Service in multiple packages

Published Apr 6, 2021
CVE-2025-68613

n8n Vulnerable to Remote Code Execution via Expression Injection

Published Dec 22, 2025
CVE-2026-27577

n8n: Expression Sandbox Escape Leads to RCE

Published Feb 25, 2026
CVE-2018-16483HIGH

Authentication Bypass by Spoofing in express-cart

Published Feb 7, 2019
MAL-2025-4595

Malicious code in express-authgen (npm)

Published May 30, 2025
MAL-2026-861

Malicious code in express-gueues (npm)

Published Feb 11, 2026
MAL-2026-1731

Malicious code in express-http-validator (npm)

Published Mar 18, 2026
MAL-2026-551

Malicious code in express-lists-routes (npm)

Published Jan 28, 2026
MAL-2026-2350

Malicious code in dotenv-express (npm)

Published Mar 24, 2026
MAL-2026-2361

Malicious code in env-express (npm)

Published Mar 24, 2026
MAL-2026-2362

Malicious code in env-express-cli (npm)

Published Mar 24, 2026
MAL-2025-47669

Malicious code in express-xmlrequest (npm)

Published Sep 26, 2025
Check your entire dependency tree at onceRun dependency scan →