CVE-2019-20838: Apple macOS

High severity, CVSS 7.5. EPSS: 2.8% chance of exploitation in the next 30 days.

libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.

Affected products

  • Apple macOS: before 11.0.1 (fixed in 11.0.1)
  • Pcre Pcre: before 8.43 (fixed in 8.43)
  • Splunk Universal Forwarder: from 8.2.0, before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.0.6 (fixed in 9.0.6); version 9.1.0 only

Published 2020-06-15. Last modified 2026-10-08.