CVE-2026-89162: Pcre PCRE2

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

Affected products

  • Pcre PCRE2: from 10.45, before 10.48 (fixed in 10.48); version 10.48 only

Published 2026-09-11. Last modified 2026-09-16.