Impact
The flaw resides in the pcre2_serialize_encode function of the PCRE2 regular‑expression library before version 10.48. When invoked, the function can read and expose two bytes of memory that belong to the caller, resulting in a modest information leak. The vulnerability is limited to a low‑severity scenario, reflected by a CVSS score of 2.9, and it requires that the adversary already has unsafe or local access to the system to trigger the read.
Affected Systems
PCRE:PCRE2 releases prior to 10.48, including any builds that employ pcre2_serialize_encode before the 10.48 release date.
Risk and Exploitability
The EPSS score is below 1%, indicating that exploitation attempts are expected to be very rare. Because the defect discloses only two bytes and needs pre‑existing unsafe access, the attack vector is inferred to be local or any context where the attacker can cause the library to serialize a pattern. The vulnerability is not listed in the CISA KEV catalog, and its low data volume and strict prerequisites combine to keep the overall risk modest.
OpenCVE Enrichment