CVE-2026-89161: Pcre PCRE2

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.

Affected products

  • Pcre PCRE2: before 10.48 (fixed in 10.48); version 10.48 only

Published 2026-09-11. Last modified 2026-09-16.