OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-103111

HIGH · CVSS 7.6 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects PCRE2 versions prior to 10.49, where improper handling of attacker-controlled regular expressions in conjunction with specific JIT API usage can lead to out-of-bounds writes, potentially allowing arbitrary data to be written. This flaw poses a significant risk as it could be exploited to execute arbitrary code or cause application crashes. Organizations utilizing PCRE2 in their applications, particularly those relying on JIT compilation, should prioritize patching to mitigate this high-severity threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103111
Severity
HIGH
CVSS
7.6
EPSS
0.21%

Original NVD Description

PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.