CVE-2026-89161
CVE-2026-89161 is a high-severity vulnerability in Pcre Pcre2 with a CVSS 3.x base score of 7.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-590.
Key facts
- Severity: High (CVSS 3.x base score 7.4)
- EPSS exploit prediction: 0% (2nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-590
- Affected product: Pcre Pcre2
- Published:
- Last modified:
Description
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
Frequently asked questions
- What is CVE-2026-89161?
- In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
- How severe is CVE-2026-89161?
- CVE-2026-89161 has a CVSS 3.x base score of 7.4, rated high severity. It is exploitable over local access with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-89161 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (2nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-89161?
- CVE-2026-89161 primarily affects Pcre Pcre2. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-89161?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-89161 published?
- CVE-2026-89161 was published on 2026-09-11 and last updated on 2026-09-16.
References
- https://github.com/PCRE2Project/pcre2/pull/937
- https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48
Affected products (2)
- cpe:2.3:a:pcre:pcre2:*:*:*:*:*:*:*:*
- cpe:2.3:a:pcre:pcre2:10.48:rc1:*:*:*:*:*:*
More vulnerabilities in Pcre Pcre2
- CVE-2017-8786 — Critical (CVSS 9.8): pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or…
- CVE-2017-8399 — Critical (CVSS 9.8): PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a…
- CVE-2015-3210 — Critical (CVSS 9.8): Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code…
- CVE-2016-3191 — Critical (CVSS 9.8): The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22…
- CVE-2025-58050 — Critical (CVSS 9.1): The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a…
- CVE-2022-1587 — Critical (CVSS 9.1): An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of…
All CVEs affecting Pcre Pcre2 →
Other CWE-590 vulnerabilities
- CVE-2026-95311 — Critical (CVSS 9.6): Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social…
- CVE-2025-32911 — Critical (CVSS 9.0): A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition()…
- CVE-2026-20810 — High (CVSS 7.8): Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to…
- CVE-2025-54899 — High (CVSS 7.8): Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-42995 — High (CVSS 7.5): SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read…
- CVE-2025-42994 — High (CVSS 7.5): SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory…