re2
npm4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting re2page 1 of 1
- CVE-2026-67550MEDIUMCVSS 5.7EG 5.7✓ Fixed in 1.25.22026-07-30
re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split…
- CVE-2026-68499MEDIUMCVSS 6.2EG 6.2✓ Fixed in 1.25.22026-07-30
re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in…
- CVE-2026-71430MEDIUMCVSS 6.2EG 6.2✓ Fixed in 1.25.12026-08-06
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that V…
- CVE-2026-71498MEDIUMCVSS 5.1EG 5.1✓ Fixed in 1.26.12026-08-06
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end of the a…
Check whether re2 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for re2 CVEs against the assets you own.
Start Free Scan →