cbcvebase.
CVE-2026-86145
published 2026-09-05

CVE-2026-86145: PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size…

PriorityP348high8.2CVSS 3.1
AVNACLPRNUINSUCNIHAL
EPSS
0.37%
30.6th percentile
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).

Affected

1 ranges
VendorProductVersion rangeFixed in
pcrepcre2>= 10.32 < 10.4810.48
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.