PatchSiren

PCRE2Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH PCRE2Project CVE published 2026-09-30

CVE-2026-103111

CVE-2026-103111 PCRE2 Out-of-Bounds Write Vulnerability. PCRE2 before 10.49 allows an out-of-bounds write with arbitrary data when there is an attacker-controlled regular expression and certain JIT API usage. This vulnerability requires assessment and patching for systems using JIT API usage, with potential for arbitrary data writes and code execution. Defenders and developers should review the supplied o [truncated]