CVE-2025-58050CRITICAL 9.1EPSS p47.0%

CVE-2025-58050CVE-2025-58050

Description

The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in src/pcre2_match.c. This vulnerability may potentially lead to information disclosure if the out-of-bounds data read during the memcmp affects the final match result in a way observable by the attacker. This issue has been resolved in version 10.46.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS0.67% probability of exploitation · percentile 47.0% · 2026-06-18T12:00:27Z
Published2025-08-27
Last modified2025-09-09

Underlying weaknesses· 3

CWE-122CWE-125CWE-787

References

  1. https://github.com/PCRE2Project/pcre2/commit/a141712e5967d448c7ce13090ab530c8e3d82254
  2. https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.46
  3. https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-c2gv-xgf5-5cc2
  4. https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-c2gv-xgf5-5cc2

3

TypeTargetConfidenceTier
WeaknessHeap-based Buffer Overflowcwe-1220%live
WeaknessOut-of-bounds Readcwe-1250%live
WeaknessOut-of-bounds Writecwe-7870%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-5450
CVE
CVE-2025-25723
CVE
CVE-2025-10451
CVE
CVE-2025-54617
CVE
CVE-2025-57052
CVE
CVE-2025-27060
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.