MEDIUMCVSS 5.7Vulnerability
CVE-2026-67550
re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII subject to trigger an out-of-bounds heap read and an uncatchable process crash, with limited heap information disclosure in some cases. This issue is fixed in 1.25.2.
Properties
- summary
- re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)
- severity
- MEDIUM
- epss_score
- 0.0018
- cvss_score
- 5.7
- ghsa_published
- 2026-07-31T16:53:16Z
- source_url
- https://github.com/advisories/GHSA-ff84-5f28-78qj
- ghsa_updated
- 2026-07-31T16:53:16Z
- ghsa_id
- GHSA-ff84-5f28-78qj
- score
- 5.7
- cve_id
- CVE-2026-67550
- cvss_vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
- signal_observed_at
- 2026-09-11T17:54:55+00:00
- is_ghsa_only
- false
- vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
- published_at
- 2026-07-30T20:18:15.030
- last_modified
- 2026-09-10T20:30:11.423
- epss_percentile
- 0.07758
Related Entities (6)
DESCRIBED_BY (1)
→[Source]NVD
ENRICHED_BY (1)
→[Source]FIRST EPSS
VULNERABLE_TO (1)
←[Software]npm/re2
AFFECTS (1)
→[Software]npm/re2
HAS_WEAKNESS (1)
→[Weakness]Out-of-bounds Read
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph