Vulnerabilidades en PCRE
7 resultadosAnálisis Vexday
A PCRE apresenta um perfil de risco muito reduzido com apenas 1 CVE registrada na base, sem evidências de exploração ativa em campo. A vulnerabilidade, recentemente publicada, relaciona-se a mecanismos de sandbox/isolamento (CWE-424), representando um risco teórico que não demanda ação imediata.
CVE-2026-86145HIGHPCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching worksEPSS 0.4%CVE-2026-89156LOWPCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.EPSS 0.2%CVE-2026-89158MEDIUMPCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.EPSS 0.2%CVE-2026-89157MEDIUMPCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.EPSS 0.2%CVE-2026-89160LOWPCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.EPSS 0.2%CVE-2026-89161HIGHIn PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can EPSS 0.1%CVE-2026-89162LOWIn PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available EPSS 0.1%