CVE-2026-71498Medium· 5.1▾ Sunlitnode-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end of the…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 28.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
0.2% → 0.2%
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end of the allocated buffer while attempting to decode the final, incomplete code point. This could result in an out-of-bounds read and potential disclosure of adjacent memory contents. This issue is fixed in version 1.26.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
re2 <= 1.26.0Patched in:
re2 1.26.1Source: https://github.com/advisories/GHSA-j4r3-hg7j-8chg
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-71430Medium· 6.2node-re2 provides RE2 regular expression bindings for Node.js
CVE-2026-92925High· 7.1A flaw was found in Redis community
CVE-2026-85234High· 7.5A flaw was found in tftp-hpa
CVE-2026-91786Medium· 6.1A flaw was found in GNOME Shell
CVE-2026-90994Medium· 4.0A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data()
CVE-2021-47996High· 7.5Rejected reason: This CVE ID has been rejected as a duplicate.