A AegiFlow
MEDIUMCVSS 5.7EPSS 0.1%

CVE-2026-67550

CVE-2026-67550 updated by NVD

Published
2026-07-31
Modified
2026-09-12
EPSS percentile
2%
Sources
github-advisory, nvd

Summary

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII subject to trigger an out-of-bounds heap read and an uncatchable process crash, with limited heap information disclosure in some cases. This issue is fixed in 1.25.2.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmre21.25.2

Remediation: Upgrade to 1.25.2 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.