THREAT OPS › Threat News › [NVD] CVE-2026-86145 (HIGH 8.2) — PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attac
[NVD] CVE-2026-86145 (HIGH 8.2) — PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attac
CVE-2026-86145 CVSS: 8.2 HIGH Published: 2026-09-05T06:17:10.370
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive patt
Indicators of compromise
- CVE-2026-86145cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86145