
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-103111 is an out-of-bounds write vulnerability in PCRE2's JIT (Just-In-Time) compiler that can be triggered by an attacker-controlled regular expression when certain JIT API configurations are in use. It affects all PCRE2 versions up to and including 10.48, and is fixed in version 10.49. The vulnerability was reported by Michael Allen, with the fix developed by Zoltan Herczeg; it was publicly disclosed on September 30, 2026. It carries a CVSS v3.1 base score of 7.6 (High) (PCRE2 Advisory, Github Advisory).
The root cause is an out-of-bounds write (CWE-787) in PCRE2's JIT stack management. The JIT stack grows downward; before reserving a frame, generated code subtracts the required frame size from the current stack top and compares it against the stack limit. If the new top is below the limit, a shared resize stub lowers the limit by a fixed 8,192 bytes — but this fixed increment is insufficient when a single frame allocation exceeds 8,192 bytes. The resize can succeed and return even though the already-adjusted stack top remains below the new limit, causing subsequent writes to occur outside the permitted stack area. Exploitation requires the application to: (1) enable JIT compilation, (2) create a growable JIT stack via pcre2_jit_stack_create(), (3) assign it using pcre2_jit_stack_assign(), and (4) allow an attacker to supply a regular expression — patterns with very large numbers of capturing groups (e.g., 1,400 distinct referenced captures) can trigger the oversized frame allocation. A standalone C proof-of-concept (pcre2_10_48_jit_stack_underwrite_poc.c) was developed by the reporter and confirmed the issue on Linux/AArch64, macOS/ARM64, and macOS/x86_64 (PCRE2 Advisory).
Successful exploitation results in an out-of-bounds write with data derived from JIT matching state, which can corrupt adjacent memory regions. Consequences include process crashes (availability impact) and memory corruption that may remain undetected until corrupted data is later used, potentially enabling arbitrary code execution in the context of the application using PCRE2 (integrity and confidentiality impact). The reporter demonstrated command execution through phpMyAdmin's use of an attacker-controlled regular expression as a real-world exploitation scenario, indicating that any application accepting user-supplied regex patterns and using the affected JIT API is at risk (PCRE2 Advisory).
No public proof-of-concept exploit code has been released, and there is no evidence of active in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. However, a private PoC was developed by the original reporter (Michael Allen) and confirmed on multiple platforms, and the advisory notes that further exploitation including arbitrary code execution should be assumed possible (PCRE2 Advisory, Feedly).
pcre2_jit_stack_create() assigned with pcre2_jit_stack_assign() — web applications like phpMyAdmin are known examples.PCRE2_ERROR_JIT_STACKLIMIT (-46), but only after the out-of-bounds writes have occurred.PCRE2_ERROR_JIT_STACKLIMIT (-46) return codes from regex matching operations, especially when triggered by user-supplied patterns; unexpected application crashes or segmentation faults in processes using PCRE2.malloc abort messages).(...) groups or deep recursion constructs like (?R)).core.*) in application working directories following regex processing operations (PCRE2 Advisory).Upgrade PCRE2 to version 10.49 or later, which contains the fix in commit 2b4038298072684b0fae29b15bedfb1a75bda46d. Backport patches for supported earlier releases are documented in the project's SUPPORT-LIFECYCLE.md. If immediate upgrading is not feasible, the following workarounds can be applied: (1) do not JIT-compile attacker-controlled regular expressions; (2) avoid assigning a growable JIT stack — allow JIT matching to use the default machine stack instead; or (3) disable JIT matching entirely by passing PCRE2_NO_JIT to pcre2_match(). Note that increasing the maximum JIT stack size is explicitly not a reliable workaround (PCRE2 Advisory, Red Hat Bugzilla).
Red Hat has opened a tracking bug (BZ#2543797) and assigned it high severity, with 17 users on the CC list indicating broad internal attention across RHEL and OpenShift product teams. The PCRE2 maintainer's advisory notes that the vulnerability is not specific to phpMyAdmin and may affect other PHP software and any software using PCRE2, broadening the potential impact scope. Social media activity was observed on Mastodon shortly after disclosure (Red Hat Bugzilla, PCRE2 Advisory).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
pcre2
devel
pcre2
focal (esm-infra)
pcre2
jammy
pcre2
noble
pcre2
resolute
pcre2
xenial (esm-apps-legacy)
pcre2
OpenShift
openshift/ose-rhel-coreos-8
RHEL 8
mariadb:10.11/mariadb.src
RHEL 9
mariadb:10.11/mariadb.src
RHEL 10
mariadb10.11.src
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."