CVE-2025-58050Patch(pcre / pcre2)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pcre pcre2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in src/pcre2_match.c. This vulnerability may potentially lead to information disclosure if the out-of-bounds data read during the memcmp affects the final match result in a way observable by the attacker. This issue has been resolved in version 10.46.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-125CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pcre2

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
pcre2

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-16: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-16: 104-16
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    PCRE2 is in grep, Postfix, Apache, and systemd. CVE-2025-58050 (heap overflow) was just patched. CVSS: 9.1. But this won't be the last PCRE2 bug. Read more: 👉 https://tinyurl.com/ywzafbrk #OpenSUSE https://t.co/E5XCGAOsXJ

    Post summary

    The tweet reports that CVE-2025-58050, a heap overflow in PCRE2 used by several major packages, has been patched and carries a CVSS score of 9.1, while warning that additional PCRE2 bugs are expected.

    00010449
    1.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppcrepcre210.45--

Explore more