PCRE2
8 known vulnerabilities in PCRE2, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-103111 CVSS 7.6 high PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with…
- CVE-2026-89162 CVSS 3.3 low In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access…
- CVE-2026-89161 CVSS 7.8 high In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation…
- CVE-2026-89160 CVSS 6.5 medium PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.
- CVE-2026-89158 CVSS 6.5 medium PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
- CVE-2026-89157 CVSS 7.4 high PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.
- CVE-2026-89156 CVSS 5.9 medium PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.
- CVE-2026-86145 CVSS 8.2 high PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching…