{ "schema_version": "1.4.0", "id": "GHSA-6hxr-mr5r-9836", "modified": "2026-07-31T16:53:08Z", "published": "2026-07-31T16:53:08Z", "aliases": [ "CVE-2026-68499" ], "summary": "re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)", "details": "## Summary\n\n`String.prototype.match` with a **global** `RE2` collects all matches in a native loop that advances the cursor by the match length. A **zero-width (empty) match** has length 0, so the cursor never advances: the same empty match is found forever and appended to an ever-growing native vector. Any pattern that can match the empty string (`a*`, `b?`, `x{0,3}`, `(a)|`, `(?:)`, …) therefore causes an infinite loop with unbounded memory growth. The call is synchronous native code, so it blocks the entire event loop and cannot be interrupted by `try/catch`, `AbortController`, `--max-old-space-size`, or timers — the process must be killed externally. This diverges from the built-in engine, where `'xxxx'.match(/a*/g)` returns a finite array.\n\n## Root cause\n\n```cpp\n// lib/match.cc:44 — global branch of WrappedRE2::Match\nwhile (re2->regexp.Match(str, byteIndex, str.size, anchor, &match, 1)) {\n groups.push_back(match);\n byteIndex = match.data() - str.data + match.size(); // += 0 for a zero-width match\n}\n```\n\nWhen `match.size() == 0`, `byteIndex` is unchanged, so the next iteration matches the same empty position again; `groups` grows without bound. The other iteration paths already guard this: `lib/split.cc:50-55` advances by `getUtf8CharSize` on an empty match, and `exec` advances `lastIndex`. Only this global `Match` loop is missing the guard.\n\n## Proof of concept\n\n```js\nconst RE2 = require('re2');\n'x'.match(new RE2('a*', 'g')); // never returns; grows memory until OOM\n// also: 'b?', 'x{0,3}', '(a)|', 'c*d*', '(?:)'; empty subject '' triggers it too\n```\n\nCompare with the built-in engine, which terminates:\n\n```js\n'xxxx'.match(/a*/g); // -> [\"\", \"\", \"\", \"\", \"\"]\n```\n\nMeasured on a clean `npm install re2@1.25.1` (latest), stock prebuilt binary: resident memory grew **~550 MB → 2.3 GB in ~3 seconds** at 100% CPU, and the process had to be `SIGKILL`ed externally.\n\n## Impact\n\nDenial of service. Reachable remotely and without authentication wherever an application runs a **global** `RE2` through `String.prototype.match` and either the pattern or the subject is attacker-influenced — e.g. a user-supplied regular expression, or a fixed empty-matchable pattern applied to user input. Because the loop blocks the event loop and exhausts memory in seconds, a single request can wedge a worker and, via memory exhaustion, affect the whole host.\n\n## Suggested fix\n\nMirror the empty-match handling already present in `split.cc`: when the match is zero-width, advance the cursor by one code point.\n\n```cpp\n// lib/match.cc, inside the global while-loop\ngroups.push_back(match);\nsize_t off = match.data() - str.data;\nif (match.size()) {\n byteIndex = off + match.size();\n} else {\n byteIndex = off + (off < str.size ? getUtf8CharSize(str.data[off]) : 1);\n}\n```\n\n## Resolution\n\nFixed in re2 1.25.2.\n\nThe global match loop in `lib/match.cc` now advances the cursor by one Unicode\ncode point when a match is zero-width, so a pattern that can match the empty\nstring terminates with a finite result identical to the built-in engine\n(`'xxxx'.match(/a*/g)` returns five empty strings). This mirrors the guard\nalready present in `split`.\n\n**Remediation:** upgrade to `re2@1.25.2` or later.\n\n**Workaround** (if you cannot upgrade): do not run a global `RE2` through\n`String.prototype.match` when the pattern is attacker-influenced or can match\nthe empty string. Iterate with `matchAll`/`exec`, or use the non-global form;\nboth already advanced the cursor correctly.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], "affected": [ { "package": { "ecosystem": "npm", "name": "re2" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "fixed": "1.25.2" } ] } ], "database_specific": { "last_known_affected_version_range": "<= 1.25.1" } } ], "references": [ { "type": "WEB", "url": "https://github.com/uhop/node-re2/security/advisories/GHSA-6hxr-mr5r-9836" }, { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68499" }, { "type": "WEB", "url": "https://github.com/uhop/node-re2/commit/56293de4fc0914d7bc35f92e98de25b0d9bb417d" }, { "type": "PACKAGE", "url": "https://github.com/uhop/node-re2" }, { "type": "WEB", "url": "https://github.com/uhop/node-re2/releases/tag/1.25.2" } ], "database_specific": { "cwe_ids": [ "CWE-835" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2026-07-31T16:53:08Z", "nvd_published_at": "2026-07-30T21:18:12Z" } }