CVE-2026-103111EPSS p10.7%
CVE-2026-103111CVE-2026-103111
Description
PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.
Scoring
| CVSS | 7.6 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
| EPSS | 0.21% probability of exploitation · percentile 10.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-04 |