{"id":"CVE-2019-20838","title":"libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \\X or \\R has more than one fixed quantifier, a related issue to CVE-2019-20454.","summary":"libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \\X or \\R has more than one fixed quantifier, a related issue to CVE-2019-20454.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-125"],"vendor":"pcre","product":"pcre","affected":["pcre < 8.43","macos < 11.0.1","universal_forwarder >= 8.2.0, < 8.2.12","universal_forwarder >= 9.0.0, < 9.0.6","universal_forwarder = 9.1.0"],"patched":["pcre 8.43","macos 11.0.1","universal_forwarder 9.0.6"],"published":"2020-06-15","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:54.420","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-20838","references":[{"url":"http://seclists.org/fulldisclosure/2020/Dec/32","label":"cve@mitre.org"},{"url":"http://seclists.org/fulldisclosure/2021/Feb/14","label":"cve@mitre.org"},{"url":"https://bugs.gentoo.org/717920","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","label":"cve@mitre.org"},{"url":"https://support.apple.com/kb/HT211931","label":"cve@mitre.org"},{"url":"https://support.apple.com/kb/HT212147","label":"cve@mitre.org"},{"url":"https://www.pcre.org/original/changelog.txt","label":"cve@mitre.org"},{"url":"http://seclists.org/fulldisclosure/2020/Dec/32","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2021/Feb/14","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugs.gentoo.org/717920","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT211931","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT212147","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.pcre.org/original/changelog.txt","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.0277,"epssPercentile":0.85902,"ingestedAt":"2026-10-08T23:16:47.306Z","slug":"CVE-2019-20838","body":"## Overview\n\nlibpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \\X or \\R has more than one fixed quantifier, a related issue to CVE-2019-20454.\n\n## Affected\n\n- `pcre < 8.43`\n- `macos < 11.0.1`\n- `universal_forwarder >= 8.2.0, < 8.2.12`\n- `universal_forwarder >= 9.0.0, < 9.0.6`\n- `universal_forwarder = 9.1.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `pcre 8.43`\n- `macos 11.0.1`\n- `universal_forwarder 9.0.6`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.6,"exploitation":0,"ransomware":0},"changes":[]}