PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.
CVSS Details
- CVSS 3.1 Base Score: 7.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade pcre2 | Oct 2, 2026 | Sep 30, 2026 |
| Debian | — | Upgrade pcre2 | Oct 1, 2026 | Sep 30, 2026 |
| Redhat_linux | — | No solution exists | Oct 1, 2026 | Sep 30, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub