CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-68499

mediumCVSS 6.2covered by 2 sourcesfirst seen 2026-07-30
Summary String.prototype.match with a global RE2 collects all matches in a native loop that advances the cursor by the match length. A zero-width (empty) match has length 0, so the cursor never advances: the same empty match is found forever and appended to an ever-growing native vector. Any pattern that can match the empty string (a*, b?, x{0,3}, (a)|, (?:), …) therefore causes an infinite loop with unbounded memory growth. The call is synchronous native code, so it blocks the entire event loop and cannot be interrupted by try/catch, AbortController, --max-old-space-size, or timers — the process must be killed externally. This diverges from the built-in engine, where 'xxxx'.match(/a*/g) returns a finite array. Root cause // lib/match.cc:44 — global branch of WrappedRE2::Match while (re2->regexp.Match(str, byteIndex, str.size, anchor, &match, 1)) { groups.push_back(match); byteIndex = match.data() - str.data + match.size(); // += 0 for a zero-width match } When match.size() == 0, byteIndex is unchanged, so the next iteration matches the same empty position again; groups grows without bound. The other iteration paths already guard this: lib/split.cc:50-55 advances by getUtf8CharSize on an empty match, and exec advances lastIndex. Only this global Match loop is missing the guard. Proof of concept const RE2 = require('re2'); 'x'.match(new RE2('a*', 'g')); // never returns; grows memory until OOM // also: 'b?', 'x{0,3}', '(a)|', 'c*d*', '(?:)'; empty subject '' triggers it too Compare with the built-in engine, which terminates: 'xxxx'.match(/a*/g); // -> ["", "", "", "", ""] Measured on a clean npm install re2@1.25.1 (latest), stock prebuilt binary: resident memory grew ~550 MB → 2.3 GB in ~3 seconds at 100% CPU, and the process had to be SIGKILLed externally. Impact Denial of service. Reachable remotely and without authentication wherever an application runs a global RE2 through String.prototype.match and either the pattern or the subject is attacker-influen

⚡ Watch CVE-2026-68499

Get an email if CVE-2026-68499 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-68499

CVE.org record

Embed the live status

CVE-2026-68499 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-68499 status](https://www.csirts.com/badge/CVE-2026-68499)](https://www.csirts.com/cve/CVE-2026-68499)