CVE-2026-103111
PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.
- Published Sep 30, 2026
- CVSS 7.6 high
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available