[Git][security-tracker-team/security-tracker][master] Add two node-re2 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 7 08:48:21 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
45d19dbb by Salvatore Bonaccorso at 2026-08-07T09:47:51+02:00
Add two node-re2 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -13,7 +13,10 @@ CVE-2026-71554 (h2 is a pure-Python implementation of a HTTP/2 protocol stack. V
 CVE-2026-71502 (CTI-Transmute contains a stored cross-site scripting vulnerability cau ...)
 	NOT-FOR-US: CTI-Transmute
 CVE-2026-71498 (node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...)
-	TODO: check
+	- node-re2 <unfixed>
+	NOTE: https://github.com/uhop/node-re2/security/advisories/GHSA-j4r3-hg7j-8chg
+	NOTE: https://github.com/uhop/node-re2/issues/272
+	NOTE: Fixed by: https://github.com/uhop/node-re2/commit/9d72042a6a0da5bc523908b04808ea0e23867cc4 (1.26.1)
 CVE-2026-71497 (jsoup is a Java library for working with real-world HTML. From 1.14.3  ...)
 	TODO: check
 CVE-2026-71488 (league/commonmark is a PHP library for parsing and rendering CommonMar ...)
@@ -43,7 +46,8 @@ CVE-2026-71434 (Statamic is a Laravel and Git powered content management system
 CVE-2026-71433 (LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres a ...)
 	NOT-FOR-US: LangGraph Checkpoint
 CVE-2026-71430 (node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...)
-	TODO: check
+	- node-re2 <unfixed>
+	NOTE: https://github.com/uhop/node-re2/security/advisories/GHSA-8hcv-x26h-mcgp
 CVE-2026-71327 (Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...)
 	TODO: check
 CVE-2026-71326 (Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45d19dbbc6d294c60dc5a35f83ec5c26dfa34c39

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45d19dbbc6d294c60dc5a35f83ec5c26dfa34c39
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260807/6e2c5f18/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list