This package has limited bug data (2 entries). Check back later or see the package health page for the full signal.

express known bugs

npm

2 known bugs in express, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.

2
bugs
Known bugs
SeverityAffectedFixed inTitleStatusSource
high5.0.05.0.1
app.use() with string path and trailing slash does not match subpaths
After the path-to-regexp 8 upgrade, `app.use('/api/', ...)` no longer matched `/api/anything`. Fixed in 5.0.1 by normalizing trailing slashes.
closedgithub:#6014
high<4.17.34.17.3
Open redirect via malformed URL
Old express versions do not sanitise certain redirect targets; upgrade to 4.17.3 or later. Also see CVE-2024-29041.
closedgithub:#4926
API access

Get this data programmatically \u2014 free, no authentication.

curl https://depscope.dev/api/bugs/npm/express
express bugs — known issues per version | DepScope | DepScope