<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:10:39 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-343461</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343461</link>
      <description>EUVD-2026-343461</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343461</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68499</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68499</link>
      <description>&lt;p&gt;re2 provides Node.js bindings for Google&amp;#39;s RE2 regular expression engine. Prior to 1.25.2, re2&amp;#39;s String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native memory growth that blocks the event loop and can exhaust host memory. This issue is fixed in 1.25.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;re2 provides Node.js bindings for Google&amp;#39;s RE2 regular expression engine. Prior to 1.25.2, re2&amp;#39;s String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native memory growth that blocks the event loop and can exhaust host memory. This issue is fixed in 1.25.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68499</guid>
    </item>
    <item>
      <title>GHSA-6hxr-mr5r-9836 — re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded nati…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6hxr-mr5r-9836</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: re2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`String.prototype.match` with a **global** `RE2` collects all matches in a native loop that advances the cursor by the match length. A **zero-width (empty) match** has length 0, so the cursor never advances: the same empty match is found forever and appended to an ever-growing native vector. Any pattern that can match the empty string (`a*`, `b?`, `x{0,3}`, `(a)|`, `(?:)`, …) therefore causes an infinite loop with unbounded memory growth. The call is synchronous native code, so it blocks the entire event loop and cannot be interrupted by `try/catch`, `AbortController`, `--max-old-space-size`, or timers — the process must be killed externally. This diverges from the built-in engine, where `&amp;#39;xxxx&amp;#39;.match(/a*/g)` returns a finite array.&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;```cpp
// lib/match.cc:44 — global branch of WrappedRE2::Match
while (re2-&amp;gt;regexp.Match(str, byteIndex, str.size, anchor, &amp;amp;match, 1)) {
    groups.push_back(match);
    byteIndex = match.data() - str.data + match.size();   // += 0 for a zero-width match
}
```&lt;/p&gt;
&lt;p&gt;When `match.size() == 0`, `byteIndex` is unchanged, so the next iteration matches the same empty position again; `groups` grows without bound. The other iteration paths already guard this: `lib/split.cc:50-55` advances by `getUtf8CharSize` on an empty match, and `exec` advances `lastIndex`. Only this global `Match` loop is missing the guard.&lt;/p&gt;
&lt;p&gt;## Proof of concept&lt;/p&gt;
&lt;p&gt;```js
const RE2 = require(&amp;#39;re2&amp;#39;);
&amp;#39;x&amp;#39;.match(new RE2(&amp;#39;a*&amp;#39;, &amp;#39;g&amp;#39;));   // never returns; grows memory unt…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: re2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`String.prototype.match` with a **global** `RE2` collects all matches in a native loop that advances the cursor by the match length. A **zero-width (empty) match** has length 0, so the cursor never advances: the same empty match is found forever and appended to an ever-growing native vector. Any pattern that can match the empty string (`a*`, `b?`, `x{0,3}`, `(a)|`, `(?:)`, …) therefore causes an infinite loop with unbounded memory growth. The call is synchronous native code, so it blocks the entire event loop and cannot be interrupted by `try/catch`, `AbortController`, `--max-old-space-size`, or timers — the process must be killed externally. This diverges from the built-in engine, where `&amp;#39;xxxx&amp;#39;.match(/a*/g)` returns a finite array.&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;```cpp
// lib/match.cc:44 — global branch of WrappedRE2::Match
while (re2-&amp;gt;regexp.Match(str, byteIndex, str.size, anchor, &amp;amp;match, 1)) {
    groups.push_back(match);
    byteIndex = match.data() - str.data + match.size();   // += 0 for a zero-width match
}
```&lt;/p&gt;
&lt;p&gt;When `match.size() == 0`, `byteIndex` is unchanged, so the next iteration matches the same empty position again; `groups` grows without bound. The other iteration paths already guard this: `lib/split.cc:50-55` advances by `getUtf8CharSize` on an empty match, and `exec` advances `lastIndex`. Only this global `Match` loop is missing the guard.&lt;/p&gt;
&lt;p&gt;## Proof of concept&lt;/p&gt;
&lt;p&gt;```js
const RE2 = require(&amp;#39;re2&amp;#39;);
&amp;#39;x&amp;#39;.match(new RE2(&amp;#39;a*&amp;#39;, &amp;#39;g&amp;#39;));   // never returns; grows memory unt…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6hxr-mr5r-9836</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68499</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68499</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-re2, Ubuntu:22.04:LTS: node-re2, Ubuntu:24.04:LTS: node-re2, Ubuntu:26.04:LTS: node-re2&lt;/p&gt;
&lt;p&gt;re2 provides Node.js bindings for Google&amp;#39;s RE2 regular expression engine. Prior to 1.25.2, re2&amp;#39;s String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native memory growth that blocks the event loop and can exhaust host memory. This issue is fixed in 1.25.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-re2, Ubuntu:22.04:LTS: node-re2, Ubuntu:24.04:LTS: node-re2, Ubuntu:26.04:LTS: node-re2&lt;/p&gt;
&lt;p&gt;re2 provides Node.js bindings for Google&amp;#39;s RE2 regular expression engine. Prior to 1.25.2, re2&amp;#39;s String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native memory growth that blocks the event loop and can exhaust host memory. This issue is fixed in 1.25.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68499</guid>
    </item>
  </channel>
</rss>
