Medium severity4.3NVD Advisory· Published Aug 20, 2026· Updated Sep 1, 2026
CVE-2026-77082
CVE-2026-77082
Description
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS) vulnerability in the Filter and Switch nodes, which compile user-supplied regex patterns with new RegExp() and execute them synchronously on the worker thread without complexity validation or execution timeout. A crafted regex pattern can block the worker for an extended period per data item processed, delaying other workflow executions on the same worker.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/n8n-io/n8n/security/advisories/GHSA-q3fv-295f-qfpfnvdMitigationVendor Advisory
- www.vulncheck.com/advisories/n8n-before-redos-via-filter-and-switch-nodenvdThird Party Advisory
News mentions
1- N8n: 18 Vulnerabilities Including Code Execution and SSRF Disclosed in BatchVypr Intelligence · Aug 20, 2026