ZeroHour
Vendor

PCRE2

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Re: pcre2 version 10.48 released with security fixes

PCRE2 10.48 ships security fixes; one issue received CVE-2026-86145 while others await identifiers amid CNA backlogs.

Salvatore Bonaccorso noted on oss-security that PCRE2 version 10.48 includes security fixes, with one issue assigned CVE-2026-86145 and remaining fixes not yet assigned identifiers. The post criticizes large CNA backlogs delaying CVE assignment, which complicates downstream fix tracking. No exploitation is reported.

oss-security · 10d agoVulnerabilityCVE-2026-86145

Related CVEs

  • Out-of-Bounds Write in PCRE2 Regular Expression Library (pcre2_dfa_match)
    PCRE2, the widely embedded Perl-compatible regular expression library, contains an out-of-bounds write in its pcre2_dfa_match function because the code path that reuses a cached workspace block skips the size check that a newly allocated block performs. Triggering the flaw requires either an attacker-controlled regular expression or a recursive pattern combined with a small heap limit set through the API, conditions that arise in applications that let users supply regex patterns or tune PCRE2's heap limit. A successful attacker can write beyond the workspace buffer, corrupting data (high integrity impact per CVSS 3.1) with only low availability impact; code execution is not documented. Any application, service, or language runtime bundling PCRE2 before 10.48 is affected, with real-world exposure concentrated in software that passes user-controlled regexes to the library. No public proof-of-concept or in-the-wild exploitation is known, EPSS puts the 30-day exploitation probability at 0.4%, and the flaw is fixed in PCRE2 10.48.
    · PCRE2 project PCRE2 All versions before 10.48 (fixed in 10.48)mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.