CVE-2026-86145: High severity PCRE2 Project PCRE2 vulnerability
PCRE2 before 10.48 allows a pcre2dfamatch out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.48-1
Event History
Frequently Asked Questions
Which deployments are realistically exposed?
Deployments using PCRE2 versions before 10.48 are affected when they invoke pcre2_dfa_match and process attacker-controlled regular expressions. They may also be exposed when recursive patterns are used together with a small heap limit configured through the API.
What does an attacker need to trigger the issue?
An attacker needs control over the regular expression, or must be able to cause matching of a recursive pattern while a small heap limit is in effect. No privileges or user interaction are indicated by the supplied severity vector.
What can be done if updating is not immediately possible?
Avoid passing attacker-controlled regular expressions to pcre2_dfa_match. Also avoid using recursive patterns with small heap limits set through the API until PCRE2 can be updated.
How can we determine whether our application is affected?
Check whether the application uses a PCRE2 release earlier than 10.48 and calls pcre2_dfa_match. Review whether regular expressions can be influenced by untrusted input, or whether recursive patterns run under small API-configured heap limits.