{"id":"CVE-2025-58050","aliases":["PYSEC-2025-259","GHSA-c2gv-xgf5-5cc2"],"title":"The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow re…","summary":"The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the han…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","vendor":"pcre2","product":"pcre2","ecosystem":"pip","affected":["pcre2 <= 10.45"],"published":"2025-08-27","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/PYSEC-2025-259","references":[{"url":"https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.46"},{"url":"https://github.com/PCRE2Project/pcre2/commit/a141712e5967d448c7ce13090ab530c8e3d82254"},{"url":"https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-c2gv-xgf5-5cc2"}],"tags":["osv","pip"],"epss":0.008,"epssPercentile":0.5464,"ingestedAt":"2026-07-13T18:58:06.795Z","slug":"CVE-2025-58050","body":"## Overview\n\nThe PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in src/pcre2_match.c. This vulnerability may potentially lead to information disclosure if the out-of-bounds data read during the memcmp affects the final match result in a way observable by the attacker. This issue has been resolved in version 10.46.\n\n## Affected packages\n\n- `pcre2 <= 10.45`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}