CVE-2026-103111
Received Received - Intake

Out-of-Bounds Write in PCRE2 Library

Vulnerability report for CVE-2026-103111, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: MITRE

Description

PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pcre2project pcre2 to 10.49 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103111 is an out-of-bounds write vulnerability in PCRE2 versions 10.48 and earlier. It occurs during JIT matching when a regex with many capturing groups triggers an oversized stack allocation. The JIT stack grows downward, and if a single allocation exceeds 8,192 bytes, memory corruption can happen below the stack region, potentially causing crashes or arbitrary code execution.

Detection Guidance

To detect this vulnerability, check if your system uses PCRE2 versions 10.48 or earlier. Run: pcre2-config --version. If the version is 10.48 or below, the system is vulnerable. Additionally, inspect applications using PCRE2 for JIT stack usage with commands like lsof or ps to identify processes loading pcre2 libraries.

Impact Analysis

An attacker could exploit this to crash applications or execute arbitrary code by providing a malicious regex pattern. This requires JIT enabled, a growable JIT stack, and attacker-controlled input. Systems using default machine stack or trusted patterns are unaffected.

Compliance Impact

This vulnerability could lead to unauthorized code execution or data corruption, potentially violating integrity and availability requirements in GDPR and HIPAA. Organizations must patch or apply mitigations to maintain compliance.

Mitigation Strategies

Upgrade PCRE2 to version 10.49 or later immediately. If upgrading is not possible, disable JIT for untrusted patterns by setting PCRE2_NO_JIT flag or using the default machine stack. Avoid using pcre2_jit_stack_create() and pcre2_jit_stack_assign() with untrusted regex patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103111. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart