CVE-2017-8786: Pcre PCRE2

Critical severity, CVSS 9.8. EPSS: 4.1% chance of exploitation in the next 30 days.

pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression.

Affected products

  • Pcre PCRE2: version 10.23 only

Published 2017-05-05. Last modified 2026-06-17.