CVE-2026-89162: Low severity PCRE2 Project PCRE2 vulnerability
In PCRE2 before 10.48, pcre2serializeencode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Exposure is limited to applications using PCRE2 versions before 10.48 that invoke pcre2_serialize_encode. The advisory notes that disclosure typically occurs where the adversary's existing access is already unsafe.
What access and conditions does an attacker need?
The vulnerability is locally exploitable and has high attack complexity, with no privileges or user interaction required according to the provided vector. Exploitation concerns pcre2_serialize_encode and may disclose two bytes.
What should be done to remediate it?
Upgrade PCRE2 to version 10.48 or later. The provided data does not identify a workaround or mitigation for deployments that cannot immediately upgrade.