Description
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
Published: 2026-09-11
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Application crash potentially leading to denial of service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability involves PCRE2’s JIT‑compiled matching routine, pcre2_jit. A previously copied subject is mishandled as a matching context; an incorrect free operation can occur. This memory misuse can cause an improper free, leading to a crash of the host application. The weakness represented by CWE-1341 (Improper Memory Deallocation) compromises application stability, though it does not directly provide arbitrary code execution.

Affected Systems

The PCRE2 regular expression library supplied by the PCRE Project is affected. Any installation of PCRE2 older than version 10.48 that uses the JIT matching feature is vulnerable. This includes numerous open‑source and commercial applications that embed PCRE2 for pattern matching.

Risk and Exploitability

The issue carries a CVSS score of 7.4, and an EPSS score of < 1% indicates a very low probability of exploitation. Nevertheless, the flaw still poses a high‑risk denial of service vector if an attacker can supply malicious regex input. The vulnerability is not listed in CISA’s KEV catalog, but its impact on If JIT compilation is disabled or not used, the risk is mitigated, but the vulnerability remains in the core library for code paths that still employ JIT.

Generated by OpenCVE AI on September 21, 2026 at 04:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PCRE2 to version 10.48 or later, which contains the corrective patch for the JIT free issue.
  • If an immediate upgrade is not feasible, disable PCRE2’s JIT compilation in the affected application by configuring the regex engine not to use JIT mode or by applying a compile‑time option that prohibits JIT.
  • Recompile or relink any applications or libraries that embed PCRE2 to use the updated version, ensuring the vulnerable code is no longer present.

Generated by OpenCVE AI on September 21, 2026 at 04:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:pcre:pcre2:10.48:rc1:*:*:*:*:*:*

Sat, 12 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Improper Leading to Application Crash pcre2: PCRE2: Memory corruption vulnerability in pcre2_jit_match
Weaknesses CWE-1341
References
Metrics threat_severity

None

threat_severity

Important


Fri, 11 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Improper Leading to Application Crash

Fri, 11 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Description In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
First Time appeared Pcre
Pcre pcre2
Weaknesses CWE-590
CPEs cpe:2.3:a:pcre:pcre2:*:*:*:*:*:*:*:*
Vendors & Products Pcre
Pcre pcre2
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-11T19:59:16.349Z

Reserved: 2026-09-11T04:11:51.278Z

Link: CVE-2026-89161

cve-icon Vulnrichment

Updated: 2026-09-11T19:59:13.713Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-11T04:18:04.470

Modified: 2026-09-16T19:10:47.780

Link: CVE-2026-89161

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T04:11:51Z

Links: CVE-2026-89161 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:00:14Z

Weaknesses
  • CWE-1341

    Multiple Releases of Same Resource or Handle

  • CWE-590

    Free of Memory not on the Heap