Out-of-Bounds Write in PCRE2 Affected by JIT API Vulnerability
CVE-2026-103111

7.6HIGH

Key Information:

Vendor

Pcre

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-103111?

PCRE2 versions prior to 10.49 are vulnerable to an out-of-bounds write due to the presence of attacker-controlled regular expressions paired with specific usages of the JIT API. This flaw can lead to arbitrary data being written outside the intended memory bounds, which may impact the stability and security of applications that utilize this library. Developers are advised to upgrade to the latest version to mitigate this risk.

Affected Version(s)

PCRE2 0 < 10.49

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.