HIGHnpm

re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)

re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)

CVE-2026-67550Published 5 days agoUpdated 5 days agoSource: OSV

Affected packages

  • re2

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.12%
EPSS percentile
2.2%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 2%.

re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS) | HackTribune