rou3 is vulnerable to Improper Resolution of Path Equivalence
85
High Risk
Affected versions of this package are vulnerable to a Path Equivalence vulnerability, where the route splitting function inadequately preserves empty segments during path processing, as evidenced by the old code that filters out empty segments using filter(Boolean), allowing attackers to bypass access restrictions and rate limits by crafting requests with multiple slashes in the URL path that are incorrectly normalized and treated as identical routes.
You are affected if you are using a version that falls within the vulnerable range.
rou3 is vulnerable to Improper Resolution of Path Equivalence in versions 0.1.0 - 0.6.3.
Upgrade the rou3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant