Количество 4
Количество 4
CVE-2026-68499
(re2 provides Node.js bindings for Google's RE2 regular expression engi ...)
CVE-2026-68499
re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native memory growth that blocks the event loop and can exhaust host memory. This issue is fixed in 1.25.2.
CVE-2026-68499
re2 provides Node.js bindings for Google's RE2 regular expression engi ...
GHSA-6hxr-mr5r-9836
re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-68499 (re2 provides Node.js bindings for Google's RE2 regular expression engi ...) | CVSS3: 6.2 | 0% Низкий | 4 дня назад | |
CVE-2026-68499 re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native memory growth that blocks the event loop and can exhaust host memory. This issue is fixed in 1.25.2. | CVSS3: 6.2 | 0% Низкий | 4 дня назад | |
CVE-2026-68499 re2 provides Node.js bindings for Google's RE2 regular expression engi ... | CVSS3: 6.2 | 0% Низкий | 4 дня назад | |
GHSA-6hxr-mr5r-9836 re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS) | CVSS3: 6.2 | 0% Низкий | 3 дня назад |
Уязвимостей на страницу