MEDIUMCVSS 5.7Vulnerability

CVE-2026-67550

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII subject to trigger an out-of-bounds heap read and an uncatchable process crash, with limited heap information disclosure in some cases. This issue is fixed in 1.25.2.

Properties

summary
re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)
severity
MEDIUM
epss_score
0.0018
cvss_score
5.7
ghsa_published
2026-07-31T16:53:16Z
source_url
https://github.com/advisories/GHSA-ff84-5f28-78qj
ghsa_updated
2026-07-31T16:53:16Z
ghsa_id
GHSA-ff84-5f28-78qj
score
5.7
cve_id
CVE-2026-67550
cvss_vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
signal_observed_at
2026-09-11T17:54:55+00:00
is_ghsa_only
false
vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
published_at
2026-07-30T20:18:15.030
last_modified
2026-09-10T20:30:11.423
epss_percentile
0.07758

Related Entities (6)

DESCRIBED_BY (1)

[Source]NVD

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]npm/re2

AFFECTS (1)

[Software]npm/re2

HAS_WEAKNESS (1)

[Weakness]Out-of-bounds Read

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-67550 (CVSS 5.7) — Ninja Signal Threat Intelligence | Ninja Signal