THREAT OPS › Threat News › [GHSA] GHSA-8hcv-x26h-mcgp (medium) — node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
[GHSA] GHSA-8hcv-x26h-mcgp (medium) — node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
GHSA-8hcv-x26h-mcgp Severity: medium CVE: CVE-2026-71430
node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
## Description
`WrappedRE2::Replace` builds the replacement result and hands it to V8 with `.ToLocalChecked()` **without checking for the empty `MaybeLocal`** that V8 ret
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-71430cve
- replace.ccdomain
Original source: https://github.com/advisories/GHSA-8hcv-x26h-mcgp