---
id: CVE-2026-103111
title: >-
  PCRE2 before 10.49, when there is an attacker-controlled regular expression
  and certain JIT API usage, allows an out-of-bounds write with arbitrary data.
summary: >-
  PCRE2 before 10.49, when there is an attacker-controlled regular expression
  and certain JIT API usage, allows an out-of-bounds write with arbitrary data.
severity: high
cvss: 7.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'
cwe:
  - CWE-787
vendor: PCRE
product: PCRE2
affected:
  - PCRE2 < 10.49
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T05:16:45.863'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103111'
references:
  - url: >-
      https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m
    label: cve@mitre.org
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-103111.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-103111'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2543797'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-103111'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103111'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ingestedAt: '2026-09-30T04:57:05.265Z'
---

## Overview

PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-30 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-103111.json)
