Description
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
Published: 2026-09-11
Score: 2.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The flaw resides in the pcre2_serialize_encode function of the PCRE2 regular‑expression library before version 10.48. When invoked, the function can read and expose two bytes of memory that belong to the caller, resulting in a modest information leak. The vulnerability is limited to a low‑severity scenario, reflected by a CVSS score of 2.9, and it requires that the adversary already has unsafe or local access to the system to trigger the read.

Affected Systems

PCRE:PCRE2 releases prior to 10.48, including any builds that employ pcre2_serialize_encode before the 10.48 release date.

Risk and Exploitability

The EPSS score is below 1%, indicating that exploitation attempts are expected to be very rare. Because the defect discloses only two bytes and needs pre‑existing unsafe access, the attack vector is inferred to be local or any context where the attacker can cause the library to serialize a pattern. The vulnerability is not listed in the CISA KEV catalog, and its low data volume and strict prerequisites combine to keep the overall risk modest.

Generated by OpenCVE AI on September 21, 2026 at 05:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PCRE2 to version 10.48 or newer.
  • Audit application code to ensure that pcre2_serialize_encode is invoked only within trusted contexts and that serialized patterns are not exposed to untrusted actors.
  • If an immediate upgrade is not possible, configure runtime controls or access restrictions to prevent untrusted users from triggering the serialization operation.

Generated by OpenCVE AI on September 21, 2026 at 05:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:pcre:pcre2:10.48:rc1:*:*:*:*:*:*

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Potential Data Disclosure in PCRE2 pcre2_serialize_encode pcre2: PCRE2: Information disclosure via pcre2_serialize_encode
Weaknesses CWE-125
References
Metrics threat_severity

None

threat_severity

Low


Fri, 11 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Potential Data Disclosure in PCRE2 pcre2_serialize_encode

Fri, 11 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
First Time appeared Pcre
Pcre pcre2
Weaknesses CWE-669
CPEs cpe:2.3:a:pcre:pcre2:*:*:*:*:*:*:*:*
Vendors & Products Pcre
Pcre pcre2
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:18:12.242Z

Reserved: 2026-09-11T04:15:03.865Z

Link: CVE-2026-89162

cve-icon Vulnrichment

Updated: 2026-09-14T14:56:59.982Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T05:16:38.697

Modified: 2026-09-16T18:56:28.643

Link: CVE-2026-89162

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-11T04:15:04Z

Links: CVE-2026-89162 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:15:09Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-669

    Incorrect Resource Transfer Between Spheres