CVE Vulnerabilities

CVE-2026-86145

Improper Protection of Alternate Path

Published: Sep 05, 2026 | Modified: Sep 09, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.2 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).

Weakness

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Hardened ImagesRedHatpcre2-main-10.48-0.1.hum1*
Pcre2Ubuntujammy*
Pcre2Ubuntuupstream*

Potential Mitigations

References