PT-2026-103020 · Pcre2 · Pcre2

CVE-2026-103111

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions PCRE2 versions prior to 10.49
Description An out-of-bounds write occurs when an attacker-controlled regular expression is used in conjunction with specific JIT API usage. This issue affects the pcre2 jit compile() and pcre2 jit match() functions, allowing the writing of arbitrary data outside the intended memory boundaries, which may lead to system crashes or potential code execution. Non-JIT matching paths are not impacted. JIT (Just-In-Time) compilation is a method used to improve performance by compiling regular expressions into machine code at runtime.
Recommendations Upgrade to version 10.49.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103111

Affected Products

Pcre2