The TRE library allows context-dependent attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression (CVE-2015-3796).
A vulnerability has been found in the tre package that could allow an attacker to perform controlled heap corruption (CVE-2016-8859).