{"id":"GHSA-6hxr-mr5r-9836","summary":"re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)","details":"## Summary\n\n`String.prototype.match` with a **global** `RE2` collects all matches in a native loop that advances the cursor by the match length. A **zero-width (empty) match** has length 0, so the cursor never advances: the same empty match is found forever and appended to an ever-growing native vector. Any pattern that can match the empty string (`a*`, `b?`, `x{0,3}`, `(a)|`, `(?:)`, …) therefore causes an infinite loop with unbounded memory growth. The call is synchronous native code, so it blocks the entire event loop and cannot be interrupted by `try/catch`, `AbortController`, `--max-old-space-size`, or timers — the process must be killed externally. This diverges from the built-in engine, where `'xxxx'.match(/a*/g)` returns a finite array.\n\n## Root cause\n\n```cpp\n// lib/match.cc:44 — global branch of WrappedRE2::Match\nwhile (re2-\u003eregexp.Match(str, byteIndex, str.size, anchor, &match, 1)) {\n    groups.push_back(match);\n    byteIndex = match.data() - str.data + match.size();   // += 0 for a zero-width match\n}\n```\n\nWhen `match.size() == 0`, `byteIndex` is unchanged, so the next iteration matches the same empty position again; `groups` grows without bound. The other iteration paths already guard this: `lib/split.cc:50-55` advances by `getUtf8CharSize` on an empty match, and `exec` advances `lastIndex`. Only this global `Match` loop is missing the guard.\n\n## Proof of concept\n\n```js\nconst RE2 = require('re2');\n'x'.match(new RE2('a*', 'g'));   // never returns; grows memory until OOM\n// also: 'b?', 'x{0,3}', '(a)|', 'c*d*', '(?:)'; empty subject '' triggers it too\n```\n\nCompare with the built-in engine, which terminates:\n\n```js\n'xxxx'.match(/a*/g);   // -\u003e [\"\", \"\", \"\", \"\", \"\"]\n```\n\nMeasured on a clean `npm install re2@1.25.1` (latest), stock prebuilt binary: resident memory grew **~550 MB → 2.3 GB in ~3 seconds** at 100% CPU, and the process had to be `SIGKILL`ed externally.\n\n## Impact\n\nDenial of service. Reachable remotely and without authentication wherever an application runs a **global** `RE2` through `String.prototype.match` and either the pattern or the subject is attacker-influenced — e.g. a user-supplied regular expression, or a fixed empty-matchable pattern applied to user input. Because the loop blocks the event loop and exhausts memory in seconds, a single request can wedge a worker and, via memory exhaustion, affect the whole host.\n\n## Suggested fix\n\nMirror the empty-match handling already present in `split.cc`: when the match is zero-width, advance the cursor by one code point.\n\n```cpp\n// lib/match.cc, inside the global while-loop\ngroups.push_back(match);\nsize_t off = match.data() - str.data;\nif (match.size()) {\n    byteIndex = off + match.size();\n} else {\n    byteIndex = off + (off \u003c str.size ? getUtf8CharSize(str.data[off]) : 1);\n}\n```\n\n## Resolution\n\nFixed in re2 1.25.2.\n\nThe global match loop in `lib/match.cc` now advances the cursor by one Unicode\ncode point when a match is zero-width, so a pattern that can match the empty\nstring terminates with a finite result identical to the built-in engine\n(`'xxxx'.match(/a*/g)` returns five empty strings). This mirrors the guard\nalready present in `split`.\n\n**Remediation:** upgrade to `re2@1.25.2` or later.\n\n**Workaround** (if you cannot upgrade): do not run a global `RE2` through\n`String.prototype.match` when the pattern is attacker-influenced or can match\nthe empty string. Iterate with `matchAll`/`exec`, or use the non-global form;\nboth already advanced the cursor correctly.","aliases":["CVE-2026-68499"],"modified":"2026-07-31T17:00:21.731310120Z","published":"2026-07-31T16:53:08Z","database_specific":{"cwe_ids":["CWE-835"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-31T16:53:08Z","nvd_published_at":"2026-07-30T21:18:12Z"},"references":[{"type":"WEB","url":"https://github.com/uhop/node-re2/security/advisories/GHSA-6hxr-mr5r-9836"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68499"},{"type":"WEB","url":"https://github.com/uhop/node-re2/commit/56293de4fc0914d7bc35f92e98de25b0d9bb417d"},{"type":"PACKAGE","url":"https://github.com/uhop/node-re2"},{"type":"WEB","url":"https://github.com/uhop/node-re2/releases/tag/1.25.2"}],"affected":[{"package":{"name":"re2","ecosystem":"npm","purl":"pkg:npm/re2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.25.2"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.25.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-6hxr-mr5r-9836/GHSA-6hxr-mr5r-9836.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}