CVE-2026-103111: High severity PCRE pcre2 vulnerability
Published Sep 30, 2026
·Updated
PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.
Affected Software
1 affected component
PCRE pcre2<10.49
Event History
Sep 30, 2026
CVE Published
via MITRE·04:13 AM
Data Sourced
via MITRE·04:13 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What conditions are required for exploitation?
An attacker must be able to supply or control a regular expression, and the affected application must use the relevant JIT API pattern. The vulnerability can be exploited over the network with low attack complexity, but it requires low-privilege access.
2
Which PCRE2 versions should be remediated?
PCRE2 versions before 10.49 are affected. Upgrade to PCRE2 10.49 or later.
3
What is the potential impact?
The flaw permits an out-of-bounds write with arbitrary data. It is rated high severity, with high integrity impact and low confidentiality and availability impact.