Sceawere
Vulnerability Detail
CVE-2026-103111UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
PCRE2 JIT Out-of-Bounds Write
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.6
- Creation Date
- 5h ago
- Vendor
- PCRE
- Product
- PCRE2
- Attack Type
- CWE-787 Out-of-bounds Write
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.6",
"pubDate": "2026-09-30T05:16:45.863Z",
"pubdate": "2026-09-30T05:16:45.863Z",
"executiveSummary": "A critical out-of-bounds memory write vulnerability exists in PCRE2 versions prior to 10.49. The vulnerability originates within the Just-In-Time (JIT) compilation component when processing specifically crafted, attacker-controlled regular expressions. By manipulating the regex pattern combined with specific JIT API usage, an attacker can trigger memory corruption, resulting in an out-of-bounds write of arbitrary data.\nThe impact of this vulnerability is severe, potentially allowing for arbitrary code execution or significant memory corruption depending on the context of the host application. It affects any environment that utilizes the PCRE2 JIT compilation engine to process regex patterns provided by untrusted or external sources. Successful exploitation requires an attacker to exert influence over the regular expression pattern passed to the library. Organizations utilizing PCRE2 should prioritize upgrading to version 10.49 or newer to mitigate the risk of exploitation.",
"technicalDetails": "The vulnerability resides in the PCRE2 JIT (Just-In-Time) compiler, which is designed to accelerate pattern matching by translating regular expression bytecodes into machine code. The flaw manifests when the JIT compiler improperly handles boundary checks or state tracking during the compilation of complex, attacker-influenced patterns.\nThe root cause involves a failure in the JIT compiler to adequately validate memory offsets or buffer boundaries when emitting machine instructions for specific regex constructs. When an attacker provides a maliciously crafted regular expression that invokes vulnerable JIT paths, the compiler may generate machine code that performs write operations outside the intended memory buffers.\nThe attack flow begins when an application accepts an unvalidated or attacker-supplied regex pattern. This pattern is passed to the PCRE2 JIT compilation API. During the JIT compilation phase, the engine calculates the required memory operations for the regex state machine. Due to the flaw, the generated JIT code includes instructions that bypass internal security bounds checks. When the compiled regex is subsequently executed against input data, these malicious JIT instructions perform an out-of-bounds write using arbitrary data provided by the attacker or dictated by the execution state.\nBecause the write operation is controlled by the attacker-supplied regex pattern and the JIT-generated machine code, an attacker can influence both the target memory address (within the scope of the JIT heap/buffer) and the data written. This type of memory corruption is typically leveraged to overwrite function pointers, internal structures, or stack data to gain control over the instruction pointer (IP/EIP/RIP).\nThis vulnerability does not strictly require local access if the application exposes a regex interface to remote clients (e.g., a web server filtering engine or a data processing service). No authentication is typically required if the vulnerable endpoint is accessible. The post-exploitation impact includes the potential for full system compromise, application crashing (Denial of Service), or arbitrary code execution under the security context of the process running the PCRE2 library."
}