Description
PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.
Published: 2026-09-11
Score: 2.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Potential Information Disclosure via Out-of-Bounds Read
Action: Apply Update
AI Analysis

Impact

The vulnerability resides in PCRE2 and triggers an out-of-bounds read during the JIT fallback path of the pcre2_match function when an attacker supplies malformed UTF data. The read can access memory locations beyond the intended bounds, which may result in exposure of arbitrary process memory contents. The weakness is identified as CWE-125.

Affected Systems

All PCRE2 builds prior to version 10.48 are affected. Any system that incorporates PCRE2 10.47 or older – including applications, libraries, or services that use PCRE2 for regular expression processing – is susceptible if they do not upgrade to 10.48 or later.

Risk and Exploitability

The CVSS score of 2.9 indicates a low severity. Since the EPSS score is not available, current exploitation activity cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog, the exploitation likelihood appears limited. The attack requires the ability to provide crafted UTF input to the PCRE2 engine; thus the vector is typically local or remote code execution contexts that involve regular expression handling.

Generated by OpenCVE AI on September 11, 2026 at 06:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PCRE2 to version 10.48 or later to apply the fix for the out-of-bounds read.
  • If an immediate upgrade is not possible, disable the JIT compilation feature in PCRE2 or configure the library to avoid JIT fallback paths, thereby preventing the vulnerable code from executing.
  • Validate that all UTF input provided to PCRE2 is well‑formed before invoking pcre2_match, ensuring malformed patterns cannot reach the susceptible fallback logic.

Generated by OpenCVE AI on September 11, 2026 at 06:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:pcre:pcre2:10.48:rc1:*:*:*:*:*:*

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title PCRE2 Out-of-Bounds Read During JIT Fallback with Invalid UTF Input PCRE2: PCRE2: Out-of-bounds read via invalid UTF data during JIT fallback
References
Metrics threat_severity

None

threat_severity

Low


Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title PCRE2 Out-of-Bounds Read During JIT Fallback with Invalid UTF Input

Fri, 11 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Description PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.
First Time appeared Pcre
Pcre pcre2
Weaknesses CWE-125
CPEs cpe:2.3:a:pcre:pcre2:*:*:*:*:*:*:*:*
Vendors & Products Pcre
Pcre pcre2
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:18:18.694Z

Reserved: 2026-09-11T04:03:05.439Z

Link: CVE-2026-89156

cve-icon Vulnrichment

Updated: 2026-09-14T14:57:03.137Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T04:18:03.230

Modified: 2026-09-16T19:27:01.327

Link: CVE-2026-89156

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-11T04:03:05Z

Links: CVE-2026-89156 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T17:30:06Z

Weaknesses