Update history
SecuritySep 14, 2026
Express patches path-to-regexp vulnerability CVE-2026-4867Express 4.22.3 updates path-to-regexp to 0.1.13, fixing CVE-2026-4867, and bumps the qs dependency to ~6.16.0, plus adds conditional revalidation support for QUERY requests.
Matters for: Teams running Express 4.x in production who need to patch known CVEs without upgrading to Express 5.
Get the badge
Show that Express is tracked on StackFollow in your project's README.
[](https://stackfollow.xyz/tools/express)