THREAT OPS › Threat News › [GHSA] GHSA-j4r3-hg7j-8chg (medium) — node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
[GHSA] GHSA-j4r3-hg7j-8chg (medium) — node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
GHSA-j4r3-hg7j-8chg Severity: medium CVE: CVE-2026-71498
node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
## Summary
`re2` infers a character's byte length from its UTF-8 lead byte alone, with no bound on the bytes actually remaining in the input. `Buffer` arguments reach the nat
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-71498cve
- replace.ccdomain
- split.ccdomain
- pattern.ccdomain
- match.ccdomain
Original source: https://github.com/advisories/GHSA-j4r3-hg7j-8chg