VYPR

node-re2

by Debian

CVEs (2)

  • CVE-2026-68499Jul 31, 2026
    risk 0.00cvss epss

    re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop…

  • CVE-2026-67550Jul 31, 2026
    risk 0.00cvss epss

    re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced…