CVE-2026-103111

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-30: 109-30
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨High - PCRE2 JIT OOB Write via Attacker-Controlled Regex (CVE-2026-103111) PCRE2 JIT (pcre2_jit_compile + pcre2_jit_match) can be driven into an out-of-bounds write when an attacker controls the pattern and the app uses the JIT API in specific ways. This enables writing attacker-chosen data out of bounds, risking crashes and potential code execution. Non-JIT matching paths are not impacted. 👉Affected: PCRE2 < 10.49 | Upgrade to 10.49

    0000036
    309 followersView on X

Explore more