Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71430

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that V8 returns when the resulting string or buffer exceeds V8's maximum string length. When a global replace uses an output amplifying replacement template, the result can grow quadratically with the input size, and once the result exceeds V8's maximum string length, the unchecked ToLocalChecked call causes a fatal, uncatchable process abort instead of a catchable exception. This issue is fixed in version 1.25.1.

A flaw was found in node-re2, a library providing RE2 regular expression bindings for Node.js. When performing a global string replacement with a specially crafted template that amplifies the output, the resulting string can exceed the maximum length allowed by the V8 JavaScript engine. This unchecked condition causes the Node.js process to terminate unexpectedly. A remote attacker could exploit this vulnerability to trigger a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3re2Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2512248re2: node-re2: Denial of Service due to excessive string length in replacements

EPSS

Процентиль: 1%
0.0011
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
25 дней назад

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that V8 returns when the resulting string or buffer exceeds V8's maximum string length. When a global replace uses an output amplifying replacement template, the result can grow quadratically with the input size, and once the result exceeds V8's maximum string length, the unchecked ToLocalChecked call causes a fatal, uncatchable process abort instead of a catchable exception. This issue is fixed in version 1.25.1.

CVSS3: 6.2
nvd
25 дней назад

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that V8 returns when the resulting string or buffer exceeds V8's maximum string length. When a global replace uses an output amplifying replacement template, the result can grow quadratically with the input size, and once the result exceeds V8's maximum string length, the unchecked ToLocalChecked call causes a fatal, uncatchable process abort instead of a catchable exception. This issue is fixed in version 1.25.1.

CVSS3: 6.2
debian
25 дней назад

node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...

CVSS3: 6.2
github
25 дней назад

node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length

EPSS

Процентиль: 1%
0.0011
Низкий

7.5 High

CVSS3