Search/CVE-2026-86145
CVE — High

CVE-2026-86145

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).

CVSS v3.1
8.2 HIGH
EPSS
0.37%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Intelligence Reports1
1 intelligence report available

Curated threat research and citations from CrowdStrike, Mandiant, Microsoft, and other sources — unlock with Premium.

Upgrade to Premium
EPSS Trend
Sep 6, 2026Sep 7, 2026
0.06pp
0.32% → 0.37% over 2 tracked changes
CVSS v3.1 Detail
Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
ConfidentialityNONE
IntegrityHIGH
AvailabilityLOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Connections
1 relationships
Timeline
disclosure → media coverage
Sep 5, 2026
Disclosure — published as a CVE record.