Browse all 7 CVE security advisories affecting uhop. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-71498 | node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript — node-re2 CWE-125 | 5.1 | Medium | 2026-08-06 |
| CVE-2026-71430 | node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length — node-re2 CWE-617 | 6.2 | Medium | 2026-08-06 |
| CVE-2026-68499 | re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS) — node-re2 CWE-835 | 6.2 | Medium | 2026-07-30 |
| CVE-2026-67550 | re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS) — node-re2 CWE-125 | 5.7 | Medium | 2026-07-30 |
This page lists every published CVE security advisory associated with uhop. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.