CVE-2026-89161
HIGHDescription
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
Is your site exposed to CVE-2026-89161?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| pcre | pcre2 |
| pcre | pcre2 |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2026-89161? +
How severe is CVE-2026-89161? +
What products are affected by CVE-2026-89161? +
How do I check if I'm vulnerable to CVE-2026-89161? +
Related Vulnerabilities
A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to …
Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access …
SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read access …
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not …
SAP MDM Server allows an attacker to gain control of existing client sessions and execute certain functions without having to …