VendorsPCREpcre210.48
Vulnerabilities

PCRE 2 10.48

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-89161
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
Published 2026-09-11 · Undergoing Analysis
7.8EPSS 0.002
CVE-2026-89157
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.
Published 2026-09-11 · Analyzed
7.4EPSS 0.004
CVE-2026-89158
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
Published 2026-09-11 · Analyzed
6.5EPSS 0.004
CVE-2026-89160
PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.
Published 2026-09-11 · Analyzed
6.5EPSS 0.004
CVE-2026-89156
PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.
Published 2026-09-11 · Analyzed
5.9EPSS 0.004
CVE-2026-89162
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
Published 2026-09-11 · Undergoing Analysis
3.3EPSS 0.002