Skip to content

FAC-101 fix: resolve high severity path-to-regexp ReDoS in NestJS v11 packages#225

Merged
y4nder merged 2 commits intodevelopfrom
claude/fix-issue-221-WpjoU
Mar 31, 2026
Merged

FAC-101 fix: resolve high severity path-to-regexp ReDoS in NestJS v11 packages#225
y4nder merged 2 commits intodevelopfrom
claude/fix-issue-221-WpjoU

Conversation

@y4nder
Copy link
Copy Markdown
Member

@y4nder y4nder commented Mar 31, 2026

Summary

  • Pin path-to-regexp to 8.4.1 via npm overrides to fix two high-severity ReDoS vulnerabilities (GHSA-j3q9-mxjg-w52f, GHSA-27v5-c462-wpq7)
  • Avoids a breaking @nestjs/swagger major version upgrade by using overrides instead of npm audit fix --force
  • All transitive consumers (@nestjs/core, @nestjs/platform-express, @nestjs/swagger, express) now resolve to 8.4.1

Test plan

  • npm audit no longer reports path-to-regexp vulnerabilities
  • npm run build passes
  • npm test — all 330 tests pass (pre-existing env validation failures unrelated)

Closes #221

https://claude.ai/code/session_01BHq6RFwCFioLF9XzNAYvRm

…vulnerabilities

Pin path-to-regexp to 8.4.1 via npm overrides to fix GHSA-j3q9-mxjg-w52f
and GHSA-27v5-c462-wpq7 without requiring a breaking @nestjs/swagger upgrade.

Closes #221

https://claude.ai/code/session_01BHq6RFwCFioLF9XzNAYvRm
@y4nder y4nder changed the title FAC-99 fix: resolve high severity path-to-regexp ReDoS in NestJS v11 packages FAC-101 fix: resolve high severity path-to-regexp ReDoS in NestJS v11 packages Mar 31, 2026
@y4nder y4nder self-assigned this Mar 31, 2026
@y4nder y4nder merged commit d5e8f76 into develop Mar 31, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

FAC-101 fix: resolve high severity path-to-regexp ReDoS in NestJS v11 packages

2 participants