Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-67550— re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)

Quick assessment

Affected
uhop node-re2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

re2 为 Google 的 RE2 正则表达式引擎提供了 Node.js 绑定。在 1.25.2 版本之前,re2 将 参数与输入字符串的 UTF-8 字节长度进行校验,但在执行 、 、 、 和 操作时,却将其当作 UTF-16 代码单元偏移量使用。这种不一致性使得攻击者可以通过控制非 ASCII 输入字符串上的 值,触发越界堆内存读取(heap read)并导致进程崩溃,且该崩溃无法被捕获。在某些情况下,该漏洞还可能泄露有限的堆信息。此问题已在版本 1.25.2 中得到修复。

CVSS 5.7 · Medium EPSS 0.16% · P5

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 1

VendorProduct Version RangeStatus
uhop node-re2 < 1.25.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-67550

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)
Source: CVE Program / CVE List V5
Vulnerability Description
re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII subject to trigger an out-of-bounds heap read and an uncatchable process crash, with limited heap information disclosure in some cases. This issue is fixed in 1.25.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
uhop node-re2 < 1.25.2 -

II. Public POCs for CVE-2026-67550

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-67550

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-67550 (1)

Vendor Advisories for CVE-2026-67550 (1)

Vendor Pages for CVE-2026-67550 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-67550

No comments yet


Leave a comment