Out-of-Bounds Read Vulnerability in PCRE2 by PCRE2 Project
CVE-2026-89160

3.7LOW

Key Information:

Vendor

Pcre

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89160?

The vulnerability in versions prior to 10.48 of PCRE2 involves an out-of-bounds read that can occur during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF-8 subject. This flaw may allow attackers to exploit the regex engine, potentially leading to unexpected behavior or exposure of sensitive data.

Affected Version(s)

PCRE2 10.34 < 10.48

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.