Re2c is a lexer generator tool embedded in build pipelines and codebases across diverse software projects, where vulnerabilities concentrate in the core product around out-of-bounds writes and uncontrolled recursion in its code-generation logic. The narrow but structurally important role this tool plays in preprocessing source code means that flaws affecting it can propagate downstream to compiled artifacts, warranting attention despite its focused footprint. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Re2c over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23901CRITICAL A stack overflow re2c 2.2 exists due to infinite recursion issues in src/dfa/dead_rules.cc. | Mar 29, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-11958HIGH re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme. | Apr 21, 2020 | 7.8 | 26 | NO | NO |
CVE-2018-21232MEDIUM re2c before 2.0 has uncontrolled recursion that causes stack consumption in find_fixed_tags. | Apr 29, 2020 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Re2c.
Media articles that mention a CVE ID that affects a product developed by Re2c — matched by CVE ID, not by vendor name.