Vulnerability Description
re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native memory growth that blocks the event loop and can exhaust host memory. This issue is fixed in 1.25.2.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/uhop/node-re2/commit/56293de4fc0914d7bc35f92e98de25b0d9bb417d
- https://github.com/uhop/node-re2/releases/tag/1.25.2
- https://github.com/uhop/node-re2/security/advisories/GHSA-6hxr-mr5r-9836
- https://github.com/uhop/node-re2/security/advisories/GHSA-6hxr-mr5r-9836
FAQ
What is CVE-2026-68499?
CVE-2026-68499 is a vulnerability with a CVSS score of 6.2 (MEDIUM). re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails t...
How severe is CVE-2026-68499?
CVE-2026-68499 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-68499?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.