CVE-2026-103111: Pcre PCRE2

High severity, CVSS 7.6. EPSS: 0.2% chance of exploitation in the next 30 days.

PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.

Affected products

  • Pcre PCRE2: before 10.49 (fixed in 10.49)

Published 2026-09-30. Last modified 2026-10-04.