[Pkg-javascript-devel] Bug#1143901: node-re2: CVE-2026-71430 CVE-2026-71498
Salvatore Bonaccorso
carnil at debian.org
Sat Aug 8 09:28:10 BST 2026
Source: node-re2
Version: 1.25.0+~cs1.6.0-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Hi,
The following vulnerabilities were published for node-re2.
CVE-2026-71430[0]:
| node-re2 provides RE2 regular expression bindings for Node.js. Prior
| to version 1.25.1, the WrappedRE2::Replace function built its
| replacement result and passed it to V8 using ToLocalChecked without
| checking for the empty MaybeLocal that V8 returns when the resulting
| string or buffer exceeds V8's maximum string length. When a global
| replace uses an output amplifying replacement template, the result
| can grow quadratically with the input size, and once the result
| exceeds V8's maximum string length, the unchecked ToLocalChecked
| call causes a fatal, uncatchable process abort instead of a
| catchable exception. This issue is fixed in version 1.25.1.
CVE-2026-71498[1]:
| node-re2 provides RE2 regular expression bindings for Node.js. Prior
| to version 1.26.1, passing a Buffer whose final bytes form a
| truncated (incomplete) multi-byte UTF-8 sequence could cause the
| native binding to read past the end of the allocated buffer while
| attempting to decode the final, incomplete code point. This could
| result in an out-of-bounds read and potential disclosure of adjacent
| memory contents. This issue is fixed in version 1.26.1.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-71430
https://www.cve.org/CVERecord?id=CVE-2026-71430
[1] https://security-tracker.debian.org/tracker/CVE-2026-71498
https://www.cve.org/CVERecord?id=CVE-2026-71498
Regards,
Salvatore
More information about the Pkg-javascript-devel
mailing list