CVE-2015-3210: Pcre

Critical severity, CVSS 9.8. EPSS: 9.2% chance of exploitation in the next 30 days.

Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/, a different vulnerability than CVE-2015-8384.

Affected products

  • Pcre Pcre: version 8.34 only; version 8.35 only; version 8.36 only; version 8.37 only
  • Pcre PCRE2: version 10.10 only

Published 2016-12-13. Last modified 2026-06-17.