CVE Vulnerabilities

CVE-2026-68499

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jul 30, 2026 | Modified: Jul 31, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

re2 provides Node.js bindings for Googles RE2 regular expression engine. Prior to 1.25.2, re2s String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native memory growth that blocks the event loop and can exhaust host memory. This issue is fixed in 1.25.2.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

References