{"id":"CVE-2026-103111","published":"2026-09-30T05:16:45.863","lastModified":"2026-09-30T05:16:45.863","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.","cvssScore":7.6,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","cwes":["CWE-787"],"vendors":[],"products":[],"references":[{"url":"https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","tags":[]}],"exploitRefs":[{"url":"https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","tags":[]}],"hasPoc":true,"ai":null}