<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:08:49 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-343528</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343528</link>
      <description>EUVD-2026-343528</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343528</guid>
    </item>
    <item>
      <title>fkie_cve-2026-67550</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-67550</link>
      <description>&lt;p&gt;re2 provides Node.js bindings for Google&amp;#39;s RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII subject to trigger an out-of-bounds heap read and an uncatchable process crash, with limited heap information disclosure in some cases. This issue is fixed in 1.25.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;re2 provides Node.js bindings for Google&amp;#39;s RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII subject to trigger an out-of-bounds heap read and an uncatchable process crash, with limited heap information disclosure in some cases. This issue is fixed in 1.25.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-67550</guid>
    </item>
    <item>
      <title>GHSA-ff84-5f28-78qj — re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → unca…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ff84-5f28-78qj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: re2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`re2` validates the user-settable `lastIndex` against the subject&amp;#39;s **UTF-8 byte length** but then uses it as a **UTF-16 code-unit count** to walk the subject buffer, with no bounds check. For any non-ASCII subject, the byte length is larger than the true character count, so a `lastIndex` between those two values passes validation while pointing past the end of the buffer. The subsequent walk reads out of bounds. With a large subject the read marches into unmapped memory and the process dies with **SIGABRT/SIGSEGV** — an uncatchable crash (`try/catch` cannot stop it), i.e. a denial of service for any worker/process that runs the match. In some cases the out-of-bounds bytes are copied into the returned value (a bounded, best-effort heap information leak).&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;The subject wrapper stores the UTF-8 **byte** length in `StrVal::length`:&lt;/p&gt;
&lt;p&gt;- `lib/addon.cc:200` `auto argLength = utf8Length(s, isolate);` — UTF-8 **byte** count
- `lib/addon.cc:209` `lastStringValue.reset(buffer, argSize, argLength, startFrom, false, isAscii);`&lt;/p&gt;
&lt;p&gt;`setIndex` then validates the (UTF-16) `lastIndex` against that byte length and walks the buffer by character count:&lt;/p&gt;
&lt;p&gt;```cpp
// lib/addon.cc:229
void StrVal::setIndex(size_t newIndex) {
    isValidIndex = newIndex &amp;lt;= length;   // length == UTF-8 BYTE length, not UTF-16 length
    if (!isValidIndex) { index = newIndex; byteIndex = 0; return; }
    ...
    // addon.cc:263
    byteIndex = index &amp;lt; newIndex
        ? getUtf16PositionByCounter(…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: re2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`re2` validates the user-settable `lastIndex` against the subject&amp;#39;s **UTF-8 byte length** but then uses it as a **UTF-16 code-unit count** to walk the subject buffer, with no bounds check. For any non-ASCII subject, the byte length is larger than the true character count, so a `lastIndex` between those two values passes validation while pointing past the end of the buffer. The subsequent walk reads out of bounds. With a large subject the read marches into unmapped memory and the process dies with **SIGABRT/SIGSEGV** — an uncatchable crash (`try/catch` cannot stop it), i.e. a denial of service for any worker/process that runs the match. In some cases the out-of-bounds bytes are copied into the returned value (a bounded, best-effort heap information leak).&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;The subject wrapper stores the UTF-8 **byte** length in `StrVal::length`:&lt;/p&gt;
&lt;p&gt;- `lib/addon.cc:200` `auto argLength = utf8Length(s, isolate);` — UTF-8 **byte** count
- `lib/addon.cc:209` `lastStringValue.reset(buffer, argSize, argLength, startFrom, false, isAscii);`&lt;/p&gt;
&lt;p&gt;`setIndex` then validates the (UTF-16) `lastIndex` against that byte length and walks the buffer by character count:&lt;/p&gt;
&lt;p&gt;```cpp
// lib/addon.cc:229
void StrVal::setIndex(size_t newIndex) {
    isValidIndex = newIndex &amp;lt;= length;   // length == UTF-8 BYTE length, not UTF-16 length
    if (!isValidIndex) { index = newIndex; byteIndex = 0; return; }
    ...
    // addon.cc:263
    byteIndex = index &amp;lt; newIndex
        ? getUtf16PositionByCounter(…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ff84-5f28-78qj</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-67550</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67550</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-re2, Ubuntu:22.04:LTS: node-re2, Ubuntu:24.04:LTS: node-re2, Ubuntu:26.04:LTS: node-re2&lt;/p&gt;
&lt;p&gt;re2 provides Node.js bindings for Google&amp;#39;s RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII subject to trigger an out-of-bounds heap read and an uncatchable process crash, with limited heap information disclosure in some cases. This issue is fixed in 1.25.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-re2, Ubuntu:22.04:LTS: node-re2, Ubuntu:24.04:LTS: node-re2, Ubuntu:26.04:LTS: node-re2&lt;/p&gt;
&lt;p&gt;re2 provides Node.js bindings for Google&amp;#39;s RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII subject to trigger an out-of-bounds heap read and an uncatchable process crash, with limited heap information disclosure in some cases. This issue is fixed in 1.25.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67550</guid>
    </item>
  </channel>
</rss>
