---
id: CVE-2019-20838
title: >-
  libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF
  is disabled, and \X or \R has more than one fixed quantifier, a related issue
  to CVE-2019-20454.
summary: >-
  libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF
  is disabled, and \X or \R has more than one fixed quantifier, a related issue
  to CVE-2019-20454.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-125
vendor: pcre
product: pcre
affected:
  - pcre < 8.43
  - macos < 11.0.1
  - 'universal_forwarder >= 8.2.0, < 8.2.12'
  - 'universal_forwarder >= 9.0.0, < 9.0.6'
  - universal_forwarder = 9.1.0
patched:
  - pcre 8.43
  - macos 11.0.1
  - universal_forwarder 9.0.6
published: '2020-06-15'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:16:54.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-20838'
references:
  - url: 'http://seclists.org/fulldisclosure/2020/Dec/32'
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2021/Feb/14'
    label: cve@mitre.org
  - url: 'https://bugs.gentoo.org/717920'
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT211931'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT212147'
    label: cve@mitre.org
  - url: 'https://www.pcre.org/original/changelog.txt'
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2020/Dec/32'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2021/Feb/14'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugs.gentoo.org/717920'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT211931'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT212147'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.pcre.org/original/changelog.txt'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.0277
epssPercentile: 0.85902
ingestedAt: '2026-10-08T23:16:47.306Z'
---

## Overview

libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.

## Affected

- `pcre < 8.43`
- `macos < 11.0.1`
- `universal_forwarder >= 8.2.0, < 8.2.12`
- `universal_forwarder >= 9.0.0, < 9.0.6`
- `universal_forwarder = 9.1.0`

## Remediation

Upgrade past the affected range:

- `pcre 8.43`
- `macos 11.0.1`
- `universal_forwarder 9.0.6`
