VDB
JLSEC-2026-176
JLSEC-2026-176
PUBLISHED
libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Julia | PCRE_jll | 0, 0 |
Timeline
- Apr 22, 2026 CVE Published
- Apr 22, 2026 CVE Updated
References
- http://seclists.org/fulldisclosure/2020/Dec/32 url
- http://seclists.org/fulldisclosure/2021/Feb/14 url
- https://bugs.gentoo.org/717920 url
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E url
- https://support.apple.com/kb/HT211931 url
- https://support.apple.com/kb/HT212147 url
- https://www.pcre.org/original/changelog.txt url