Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 05 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 05 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out-of-Bounds Write in PCRE2 DFA Matching Due to Cached Workspace Size Check Missing |
Sat, 05 Sep 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API). | |
| First Time appeared |
Pcre
Pcre pcre2 |
|
| Weaknesses | CWE-424 | |
| CPEs | cpe:2.3:a:pcre:pcre2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pcre
Pcre pcre2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-05T13:06:54.297Z
Reserved: 2026-09-05T05:09:25.213Z
Link: CVE-2026-86145
No data.
Status : Received
Published: 2026-09-05T06:17:10.370
Modified: 2026-09-05T14:17:23.897
Link: CVE-2026-86145
No data.
OpenCVE Enrichment
Updated: 2026-09-05T06:30:04Z