What is CVE-2026-68499?
CVE-2026-68499 is a vulnerability in the 're2' package, which provides Node.js bindings for Google's RE2 engine. In versions prior to 1.25.2, using String.prototype.match with a global pattern that matches an empty string causes an infinite loop due to a cursor advancement failure, leading to a Denial of Service (DoS). Users should immediately upgrade to version 1.25.2 or later.
Azərbaycanca: CVE-2026-68499, Node.js üçün Google RE2 kitabxanasının 're2' paketində aşkarlanmış boşluqdur. 1.25.2 versiyasından əvvəlki versiyalarda, qlobal RE2 nümunəsi boş sətirlə uyğunlaşdıqda `String.prototype.match` funksiyası sonsuz dövrəyə girərək xidmət dayanmasına (DoS) səbəb olur. Bu zəiflikdən qorunmaq üçün dərhal 1.25.2 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Google
FAQ2
Which software package is affected by CVE-2026-68499?
This vulnerability affects the 're2' package, which provides Node.js bindings for Google's RE2 engine.
What is the recommended action to mitigate CVE-2026-68499?
Users should immediately upgrade to version 1.25.2 or later to protect against this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.