This package has limited bug data (2 entries). Check back later or see the package health page for the full signal.
express known bugs
npm2 known bugs in express, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.
2
bugs
Known bugs
| Severity | Affected | Fixed in | Title | Status | Source |
|---|---|---|---|---|---|
| high | 5.0.0 | 5.0.1 | app.use() with string path and trailing slash does not match subpaths After the path-to-regexp 8 upgrade, `app.use('/api/', ...)` no longer matched `/api/anything`. Fixed in 5.0.1 by normalizing trailing slashes. | closed | github:#6014 |
| high | <4.17.3 | 4.17.3 | Open redirect via malformed URL Old express versions do not sanitise certain redirect targets; upgrade to 4.17.3 or later. Also see CVE-2024-29041. | closed | github:#4926 |
API access
Get this data programmatically \u2014 free, no authentication.
curl https://depscope.dev/api/bugs/npm/express