CVE-2017-7186: Pcre

High severity, CVSS 7.5. EPSS: 5% chance of exploitation in the next 30 days.

libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup.

Affected products

  • Pcre Pcre: version 8.40 only
  • Pcre PCRE2: version 10.23 only

Published 2017-03-20. Last modified 2026-06-17.