Integer Overflow Vulnerability in PCRE2 on 32-bit Platforms
CVE-2026-89158

6.5MEDIUM

Key Information:

Vendor

Pcre

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89158?

PCRE2 versions prior to 10.48 on 32-bit platforms are susceptible to an integer overflow flaw within the pcre2_compile_32 function. This vulnerability can potentially lead to an out-of-bounds write, which may allow attackers to execute unauthorized actions or manipulate application behavior. It is imperative for users of affected versions to upgrade to the latest release to mitigate risks associated with this security issue.

Affected Version(s)

PCRE2 0 < 10.48

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.