AZL-99726
Dashboard / Vulnerabilities / AZL-99726
Summary: CVE-2026-86145 affecting package pcre2 for versions less than 10.48-1
Details: PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).
References: https://nvd.nist.gov/vuln/detail/CVE-2026-86145
Affected packages
Package
Name: pcre2
Purl: pkg:rpm/azure-linux/pcre2
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -10.48-1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
