CVE-2017-8399: Pcre PCRE2

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."

Affected products

  • Pcre PCRE2: before 10.30 (fixed in 10.30)

Published 2017-05-01. Last modified 2026-06-17.