---
id: CVE-2020-14155
title: >-
  libpcre in PCRE before 8.44 allows an integer overflow via a large number
  after a (?C substring.
summary: >-
  libpcre in PCRE before 8.44 allows an integer overflow via a large number
  after a (?C substring.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-190
vendor: pcre
product: pcre
affected:
  - pcre < 8.44
  - macos < 11.0.1
  - gitlab < 12.10.13
  - 'gitlab >= 13.0.0, < 13.0.8'
  - 'gitlab >= 13.1.0, < 13.1.2'
  - communications_cloud_native_core_policy = 1.15.0
  - active_iq_unified_manager
  - cloud_backup
  - clustered_data_ontap
  - ontap_select_deploy_administration_utility
  - steelstore_cloud_integrated_storage
  - h410c_firmware
  - h300s_firmware
  - h500s_firmware
  - h700s_firmware
  - h410s_firmware
  - 'universal_forwarder >= 8.2.0, < 8.2.12'
  - 'universal_forwarder >= 9.0.0, < 9.0.6'
  - universal_forwarder = 9.1.0
patched:
  - pcre 8.44
  - macos 11.0.1
  - gitlab 13.1.2
  - universal_forwarder 9.0.6
published: '2020-06-15'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:23.370'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-14155'
references:
  - url: 'http://seclists.org/fulldisclosure/2020/Dec/32'
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2021/Feb/14'
    label: cve@mitre.org
  - url: >-
      https://about.gitlab.com/releases/2020/07/01/security-release-13-1-2-release/
    label: cve@mitre.org
  - url: 'https://bugs.gentoo.org/717920'
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20221028-0010/'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT211931'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT212147'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: cve@mitre.org
  - url: 'https://www.pcre.org/original/changelog.txt'
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2020/Dec/32'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2021/Feb/14'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://about.gitlab.com/releases/2020/07/01/security-release-13-1-2-release/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugs.gentoo.org/717920'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20221028-0010/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT211931'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT212147'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.pcre.org/original/changelog.txt'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.04182
epssPercentile: 0.90654
ingestedAt: '2026-10-08T22:11:53.716Z'
---

## Overview

libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

## Affected

- `pcre < 8.44`
- `macos < 11.0.1`
- `gitlab < 12.10.13`
- `gitlab >= 13.0.0, < 13.0.8`
- `gitlab >= 13.1.0, < 13.1.2`
- `communications_cloud_native_core_policy = 1.15.0`
- `active_iq_unified_manager`
- `cloud_backup`
- `clustered_data_ontap`
- `ontap_select_deploy_administration_utility`
- `steelstore_cloud_integrated_storage`
- `h410c_firmware`
- `h300s_firmware`
- `h500s_firmware`
- `h700s_firmware`
- `h410s_firmware`
- `universal_forwarder >= 8.2.0, < 8.2.12`
- `universal_forwarder >= 9.0.0, < 9.0.6`
- `universal_forwarder = 9.1.0`

## Remediation

Upgrade past the affected range:

- `pcre 8.44`
- `macos 11.0.1`
- `gitlab 13.1.2`
- `universal_forwarder 9.0.6`
