NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #76 most downloaded on npm
Express style path to RegExp utility
Last release 6 months ago
01 Apr 2026
Ships unpredictably
gaps range from 8 days to 1.9 years
Some releases are documented
notes for 34 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
73 releases · first in 2012
Error on trailing backslash ( #434 ) 9a78879
One column per quarter.
Remove trie deduplication ( #431 ) 6bc8e84
Fixed
/*foo with /a/b = /a/*foo.htmlwith /a/b.html/c.html = /a/b.html/:"a"_:"b" against /foo__. This makes intuitive sense because the second parameter is not going to backtrack on _ anymore, but it's somewhat unexpected since there's no reason it shouldn't match the second _.Fix CVE-2026-4926 ( GHSA-j3q9-mxjg-w52f )
Important
Fixed
Changed
/users{/delete} it will restrict the number of generated combinations to < 256, equivalent to 8 top-level optional groups and unlikely to occur in a real world application, but avoids exploding the regex size for applications that accept user created routesAllowing path-to-regexp to run on older browsers by targeting ES2015
Fixed
path-to-regexp to run on older browsers by targeting ES2015
Adds pathToRegexp method back for generating a regex
Added
pathToRegexp method back for generating a regexstringify method for converting TokenData into a path stringHeads up! This is a fairly large change (again) and I need to apologize in advance. If I foresaw what this version would have ended up being I would n
Heads up! This is a fairly large change (again) and I need to apologize in advance. If I foresaw what this version would have ended up being I would not have released version 7. A longer blog post and explanation will be incoming this week, but the pivot has been due to work on Express.js v5 and this will the finalized syntax used in Express moving forward.
Edit: The post is out - https://blakeembrey.com/posts/2024-09-web-redos/
Added
*name syntax, aligns with : behavior but using an asterisk insteadChanged
?, +, and * - only optional exists moving forward (use wildcards for +, {*foo} for *)Added
:"foo-bar"string | TokenData | Array<string | TokenData>Removed
loose modehttps://github.com/pillarjs/path-to-regexp/compare/v7.1.0...v8.0.0
Support array inputs for match and pathToRegexp 3fdd88f
Added
match and pathToRegexp 3fdd88fhttps://github.com/pillarjs/path-to-regexp/compare/v7.1.0...v7.2.0
Adds a strict option to detect potential ReDOS issues
Added
strict option to detect potential ReDOS issuesFixed
suffix + prefix when not specifiedTokenData
TokenData manually, previously parse filled it in automaticallyComments
strict: true and I'm probably releasing a V8 with it enabled by default ASAP as a necessary security mitigationhttps://github.com/pillarjs/path-to-regexp/compare/v7.0.0...v7.1.0
Hi all! There's a few major breaking changes in this release so read carefully.
Hi all! There's a few major breaking changes in this release so read carefully.
Breaking changes:
compile only accepts strings as values (i.e. no numbers, use String(value) before compiling a path)
encode !== false, it must be an array of strings\p{XID_Continue}).?, *, +) must be used after a param explicitly wrapped in {}
/ or .*) has been added back and matches Express.js expected behaviorendsWith optionstrict: true to trailing: false;, ,, !, and @ for future use-casestokensToRegexp, tokensToFunction and regexpToFunction in favor of simplifying exports/ can be repeated multiple times in a matched path (i.e. /foo works like //foo, etc)encode and decode no longer receive the token as the second parameterencodeURIComponent and decode defaults to decodeURIComponentAdded:
encodePath to fix an issue around encode being used for both path and parameters (the path and parameter should be encoded slightly differently)loose as an option to support arbitrarily matching the delimiter in paths, e.g. foo/bar and foo///bar should work the sameencode and decode to be set to false which skips all processing of the parameters input/outputTokenData (exported, returned by parse) as input
Requests for feedback:
{} is an obvious drawback but I'm seeking feedback on whether it helps make path behavior clearer
/ and . as implicit prefixeshttps://github.com/pillarjs/path-to-regexp/compare/v6.2.2...v7.0.0
Add backtrack protection to 6.x (#324) f1253b4
Fixed
https://github.com/pillarjs/path-to-regexp/compare/v6.2.2...v6.3.0
No API changes. Documentation only release.
No API changes. Documentation only release.
Changed
https://github.com/pillarjs/path-to-regexp/compare/v6.2.1...v6.2.2
Fix invalid matching of :name* parameter (#261) 762bc6b
Fixed
:name* parameter (#261) 762bc6bAdded
https://github.com/pillarjs/path-to-regexp/compare/v6.2.0...v6.2.1
Support named capturing groups for RegExps
Added
Fixed
strict flag documentation (#227)Use /#? as default delimiter to avoid matching on query or fragment parameters
Fixed
/#? as default delimiter to avoid matching on query or fragment parameters
delimiter: '.'This release reverts the prefix behavior added in v3 back to the behavior seen in v2. For the most part, path matching is backward compatible with v2
This release reverts the prefix behavior added in v3 back to the behavior seen in v2. For the most part, path matching is backward compatible with v2 with these enhancements:
/(abc(?=d))/{abc(.*)def}/test(foo previously worked treating ( as a literal character, now it expects ( to be closed and is treated as a group/test\(fooChanged
prefixes option to configure this (starts as /. which acts like every version since 0.x again){} to capture prefix/suffix explicitly, enables custom use-cases like /:attr1{-:attr2}?No changes to path rules since 3.x, except support for nested RegEx parts in 4.x.
No changes to path rules since 3.x, except support for nested RegEx parts in 4.x.
Changed
RegexpOptions interface to TokensToRegexpOptionsnormalizePathname from library, document solution in READMEencodeURIComponentRemove whitelist in favor of decodeURI (advanced behavior can happen outside path-to-regexp)
Removed
whitelist in favor of decodeURI (advanced behavior can happen outside path-to-regexp)Remove usage of String.prototype.normalize to continue supporting IE
Fixed
String.prototype.normalize to continue supporting IEAdd normalize whitelist of characters (defaults to /%.-)
Added
/%.-)Allow RegexpOptions in match(...) function
Fixed
RegexpOptions in match(...) functionNormalize regexp spelling across 4.x
Fixed
regexp spelling across 4.xAll path rules are backward compatible with 3.x, except for nested () and other RegEx special characters that were previously ignored.
All path rules are backward compatible with 3.x, except for nested () and other RegEx special characters that were previously ignored.
Changed
match does not default to decodeURIComponentAdded
normalizePathname utility for supporting unicode paths in librariesAdd backtrack protection to 3.x release (#321) d31670a
Fixed
https://github.com/pillarjs/path-to-regexp/compare/v3.2.0...v3.3.0
Add native match function to library
Added
match function to libraryAdd sensitive option for tokensToFunction
sensitive option for tokensToFunction (#191)validate option to path functions (#178)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add backtrack protection to 1.x release (#320) 925ac8e
Fixed
re.exec('/test/route') result (#267) 32a14b0https://github.com/pillarjs/path-to-regexp/compare/v1.8.0...v1.9.0
Backport TokensToFunctionOptions
Added
TokensToFunctionOptionsNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix CVE-2026-4867 (GHSA-37ch-88jc-xwx2)
Full Changelog: https://github.com/pillarjs/path-to-regexp/compare/v0.1.12...v.0.1.13
Improved backtracking protection for 0.1.x, will break some previously valid paths (see previous advisory: https://github.com/pillarjs/path-to-regexp/
Fixed
https://github.com/pillarjs/path-to-regexp/compare/v0.1.11...v0.1.12
Add error on bad input values 8f09549
Changed
https://github.com/pillarjs/path-to-regexp/compare/v0.1.10...v0.1.11
Your coding agent can read these notes before it upgrades. Set up the MCP server →