PatchSiren

PCRE CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW PCRE CVE published 2026-09-11

CVE-2026-89162

A low-severity vulnerability exists in PCRE2 before version 10.48, where the pcre2_serialize_encode function might disclose two bytes to an adversary in an already unsafe situation. This vulnerability affects systems using PCRE2, requiring defenders and system administrators to assess exposure and prioritize verification of PCRE2 versions in use. The vulnerability is classified as low-severity, with a CVS [truncated]

HIGH PCRE CVE published 2026-09-11

CVE-2026-89161

A high-severity vulnerability exists in PCRE2 before version 10.48, where the `pcre2_jit_match` function mishandles a previously copied subject being passed in as a context, leading to an incorrect free operation. This issue affects systems and applications using PCRE2, potentially leading to denial of service or code execution if exploited. Defenders responsible for these systems should assess exposure a [truncated]

LOW PCRE CVE published 2026-09-11

CVE-2026-89160

A low-severity vulnerability was found in PCRE2 before version 10.48, which could lead to an out-of-bounds read during the matching of an invalid UTF subject. This vulnerability affects systems using the PCRE2 library, particularly those that handle UTF subjects. Defenders should assess their exposure and consider upgrading to version 10.48 or later to mitigate potential risks. The vulnerability has a low [truncated]

MEDIUM PCRE CVE published 2026-09-11

CVE-2026-89158

CVE-2026-89158 is a medium-severity integer overflow vulnerability in PCRE2's pcre2_compile_32 function on 32-bit platforms, leading to an out-of-bounds write. This vulnerability affects deployments using PCRE2 on 32-bit systems. Defenders of these deployments should assess exposure and apply patches to prevent potential exploitation. The CVE record and NVD entry provide details on the vulnerability. Revi [truncated]

MEDIUM PCRE CVE published 2026-09-11

CVE-2026-89157

CVE-2026-89157 is a vulnerability in PCRE2 before version 10.48, affecting 32-bit platforms. It allows for an out-of-bounds write when a large pattern is provided to the pcre2_pattern_convert function. This vulnerability could potentially lead to denial of service or code execution. Defenders should verify exposure, assess remediation feasibility, and consider compensating controls. The CVE record and NVD [truncated]

LOW PCRE CVE published 2026-09-11

CVE-2026-89156

A low-severity vulnerability exists in PCRE2 before version 10.48, which could lead to an out-of-bounds read after a JIT fallback when an attacker provides invalid UTF data. This issue arises in the pcre2_match function, and defenders should assess the exposure of systems that utilize PCRE2, especially those processing user-input data, and prioritize verifying the version of PCRE2 in use. The vulnerabilit [truncated]

HIGH Pcre CVE published 2017-02-16

CVE-2017-6004

CVE-2017-6004 is a denial-of-service issue in PCRE’s JIT compilation path. According to NVD, the flaw can be triggered by a crafted regular expression and may cause an out-of-bounds read followed by an application crash. NVD rates the issue as high severity (CVSS 3.0: 7.5) with network attack vector and no privileges or user interaction required. The record links the fix to an upstream PCRE patch (revisio [truncated]