MEDIUMCVSS 6.2Vulnerability
CVE-2026-68499
re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native memory growth that blocks the event loop and can exhaust host memory. This issue is fixed in 1.25.2.
Properties
- summary
- re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)
- severity
- MEDIUM
- epss_score
- 0.00188
- cvss_score
- 6.2
- ghsa_published
- 2026-07-31T16:53:08Z
- source_url
- https://github.com/advisories/GHSA-6hxr-mr5r-9836
- ghsa_updated
- 2026-07-31T16:53:11Z
- ghsa_id
- GHSA-6hxr-mr5r-9836
- score
- 6.2
- cve_id
- CVE-2026-68499
- cvss_vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- signal_observed_at
- 2026-09-11T17:54:55+00:00
- is_ghsa_only
- false
- vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- published_at
- 2026-07-30T21:18:12.870
- last_modified
- 2026-09-10T20:30:11.423
- epss_percentile
- 0.0866
Related Entities (6)
DESCRIBED_BY (1)
→[Source]NVD
ENRICHED_BY (1)
→[Source]FIRST EPSS
VULNERABLE_TO (1)
←[Software]npm/re2
AFFECTS (1)
→[Software]npm/re2
HAS_WEAKNESS (1)
→[Weakness]Loop with Unreachable Exit Condition ('Infinite Loop')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph