CVE-2026-86145: High severity PCRE2 Project PCRE2 vulnerability

Published Sep 5, 2026
·
Updated

PCRE2 before 10.48 allows a pcre2dfamatch out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).

Affected Software

2 affected componentsFixes available
PCRE2 Project PCRE2<10.48
Microsoft azl3 pcre2 10.42-3<10.48-1
10.48-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.48-1

Event History

Sep 5, 2026
CVE Published
via MITRE·05:09 AM
Data Sourced
via MITRE·05:09 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Sep 6, 2026
Data Sourced
via Microsoft·11:37 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·11:37 AM
DescriptionSeverity

Frequently Asked Questions

1

Which deployments are realistically exposed?

Deployments using PCRE2 versions before 10.48 are affected when they invoke pcre2_dfa_match and process attacker-controlled regular expressions. They may also be exposed when recursive patterns are used together with a small heap limit configured through the API.

2

What does an attacker need to trigger the issue?

An attacker needs control over the regular expression, or must be able to cause matching of a recursive pattern while a small heap limit is in effect. No privileges or user interaction are indicated by the supplied severity vector.

3

What can be done if updating is not immediately possible?

Avoid passing attacker-controlled regular expressions to pcre2_dfa_match. Also avoid using recursive patterns with small heap limits set through the API until PCRE2 can be updated.

4

How can we determine whether our application is affected?

Check whether the application uses a PCRE2 release earlier than 10.48 and calls pcre2_dfa_match. Review whether regular expressions can be influenced by untrusted input, or whether recursive patterns run under small API-configured heap limits.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203