Out-of-Bounds Read Vulnerability in PCRE2 by PCRE Project
CVE-2026-89156

2.9LOW

Key Information:

Vendor

Pcre

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89156?

The PCRE2 library, prior to version 10.48, is susceptible to an out-of-bounds read vulnerability that can occur during a JIT fallback when invalid UTF data is supplied by an attacker. This flaw potentially allows attackers to exploit applications relying on the PCRE2 library for regular expression processing, which could lead to information disclosure or application crashes.

Affected Version(s)

PCRE2 10.34 < 10.48

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.