THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-j4r3-hg7j-8chg (medium) — node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript

[GHSA] GHSA-j4r3-hg7j-8chg (medium) — node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript

highgithub_advisoriesPublished 2026-08-06

GHSA-j4r3-hg7j-8chg Severity: medium CVE: CVE-2026-71498

node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript

## Summary

`re2` infers a character's byte length from its UTF-8 lead byte alone, with no bound on the bytes actually remaining in the input. `Buffer` arguments reach the nat

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-j4r3-hg7j-8chg