v4.22.1

expressjs/expressv4.22.1Dec 1, 2025by jonchurch

AI Summary

This patch release for the 4.x branch reverts an erroneous breaking change that was included in v4.22.0 related to the extended query parser. Similar to v5.2.1, the CVE-2024-51999 was rejected and the change has been fully reverted.

Key Highlights

  • Reverts erroneous breaking change from v4.22.0
  • CVE-2024-51999 has been rejected
  • Restores previous extended query parser behavior in 4.x

Full Release Notes

## What's Changed

> [!IMPORTANT]  
> The prior release (4.22.0) included an erroneous breaking change related to the extended query parser. There is no actual security vulnerability associated with this behavior (CVE-2024-51999 has been rejected). The change has been fully reverted in this release.

* Release: 4.22.1 by @UlisesGascon in https://github.com/expressjs/express/pull/6934


**Full Changelog**: https://github.com/expressjs/express/compare/4.22.0...v4.22.1